Skip to main content

Overview

A verification goes through several states from creation to completion.

CREATED

Verification created via POST /verifications/. The user has not yet opened the verification link.

STARTED

The user has opened the verification link. The status stays STARTED from that point, whether they keep going or abandon the flow, until their data is collected.

USER_DATA_COLLECTED

Every check the workflow requires has been collected and is now being processed by the pawaPass system.

REVIEW (optional)

Manual action is required. A pawaPass agent reviews the verification when automated checks are inconclusive.

Final status

The verification resolves to one of three final states (see below).

Final statuses

APPROVED

Identity verified. Document data extracted.

DECLINED

Failed face scan attempts or agent decision.

EXPIRED

Session expired. Default: 30 days.

Re-verifying the same user

A verification is active until it reaches one of the final statuses above. While a verification for an externalId is still active, creating another verification with the same externalId returns the existing one (200 OK) instead of starting a new flow. Once the verification reaches a final status (APPROVED, DECLINED, or EXPIRED), creating a verification with the same externalId starts a fresh one (201 Created). If short links are enabled, the new verification reuses the same url as the previous one, so any link you already shared keeps pointing to the latest verification.

Example flows

CREATED → STARTED → USER_DATA_COLLECTED → APPROVEDThe most common flow. User completes all steps, system auto-approves.
CREATED → STARTED → USER_DATA_COLLECTED → REVIEW → DECLINEDAutomated checks are inconclusive, agent reviews and declines.
CREATED → EXPIREDUser doesn’t open the verification link within the expiration window.