How the Pieces Fit
Your backend asks DAL for a session token. Your web page or mobile app resumes that session in the SDK. When capture ends, DAL notifies you by webhook. Two things in this diagram matter most:- The session already exists when you get the token. Your UI only ever resumes the session it was given.
- Completion is asynchronous. The SDK’s
onJourneyFinishedmeans the entity has finished capturing. DAL’s decision arrives seconds to a couple of minutes later, by webhook.
Step by Step
1
Generate a session token
Ask DAL to start a verification session for the entity and issue a short-lived token bound to it.
type is identity or address (case-insensitive). If the entity already has a session of this type that has not finished, DAL reuses it instead of starting another, so calling this again after a page reload simply lets the entity pick up where they left off.Endpoint: Generate international verification tokenThe token is valid for one hour. Request a new one on each visit rather than caching it; the same session is reused. DAL refuses the call with 403 when the entity is not eligible: it is blocked for this type, or the type is not enabled on your tenant. An entity can verify more than one identity document. Running an identity flow again with a document that already exists on the entity re-verifies it and refreshes its details, expiry, and images. You do not need to check eligibility yourself.2
Resume the session in your UI
Hand Keep the entity’s profile up to date before requesting a token. DAL cross-checks it against the captured document.
clientToken, flowId and trialId to your front end. Load the web SDK, mount it into an element on your page, and resume the session. See IDwise’s Web SDK usage and Resuming a journey pages for the full SDK reference.3
Receive the outcome
After the entity finishes, DAL processes the result, updates the entity, and sends you an
IntlVerificationUpdate webhook. Treat this event as the single source of truth for the session’s outcome.Payload: International verification eventOn
isFailed: false, refresh your copy of the entity with view client or view prospect to read what was written. For identity flows the item in identities for that document (new, or updated when the number already existed) has verifiedAt set, source Automatic, and type reflecting the document (Passport, NationalIdentity, ResidencyPermit, DrivingLicense, or Other). For address flows, list the entity’s addresses with list entity addresses.On isFailed: true, check verificationBlocked in the payload. If it equals type, the entity has hit a blocking rule and cannot retry until a compliance officer resets it from the DAL portal. Otherwise the entity may simply generate a new token and try again.Identity flows and KYC. If the entity has a KYC in progress, a successful identity verification also fills its nationality and country-of-residence answers and re-evaluates the KYC. A
KycStatusUpdate webhook follows only when the KYC status changes as a result: KycPending when the entity can now proceed to forms, ConsentPolicyPending when the consent policy is still unsigned, or KycBlocked when the verified nationality or issuing country is on your block list. A KYC already in KycPending with a clean nationality stays there and sends no KYC event. A blocked country is not reported as a verification failure; isFailed is false and the block appears only on the KYC.Address flows and review. When the proof-of-address document passes capture but not every validation rule, DAL still accepts it and creates the address with status
Submitted for an admin to review, rather than Verified. isFailed is false in both cases. There is no webhook for the admin’s decision; poll the address list if you need to know when it becomes Verified.4
List verification records
Every attempt is stored as a record with its outcome. Use this to build an attempt history, show failure reasons to your staff, or reconcile after a missed webhook.Endpoint: List international verification records
status is Pending (session started, no decision yet), Completed, or Failed. A Failed record with a non-null resetAt has been cleared by a reset and no longer counts toward blocking. The optional filters[status] query narrows the list to one status. The list is not paginated; all records of the requested type are returned.Resetting a blocked entity is not part of the API. Your compliance officer lifts the block from the DAL portal, which stamps
resetAt on the active Failed records and sets verificationBlocked back to null.Blocking Rules
A block stops the entity generating new tokens for that flow type until a compliance officer resets it. The rules differ by type.
DAL’s own checks count toward the identity limit like any other failure:
Invalid Identity Number, Duplicate Identity (the document number already belongs to another entity in your tenant), No verifiable document, and Blocked.
While an entity is blocked for identity, any identity session that finishes is recorded as Failed with reason Blocked. Address sessions are unaffected. A new identity session can only start after the reset.
Failure Reasons
reasons in the webhook, and failedReasons in the record list, carry the names of the checks that did not pass. They fall into four groups.
Document checks run on the captured images and extracted fields, for example Physical Document Check (Front), Document Expired, Photo Substitution Check (Front), Image Injection Check (Front), Suspicious Document (Front), Capture Quality (Front), Field Presence: Birth Date (Front), Field Format: Document Number (Front), Cross Check: Full Name, Valid Logical Dates Check, ID Document Sides Check.
Journey rules are flow-level decisions: Recognised Document, Authentic Document, Expired Document, Approved Nationality, Document Quality, Unique Applicant, Same Person, Selfie Liveness, Device Intelligence Checks.
Device signals trigger a block: App Tampering, Bot, Browser Incognito, Emulator, High Device Usage, IP Restriction, Proxy, TOR, VPN.
DAL checks run after the document is accepted: Invalid Identity Number, Duplicate Identity, No verifiable document, Blocked, Address extraction from document failed.
The record list returns each reason as an { en, ar } pair; the webhook returns the English name only.
Go-Live Checklist
- A test token request succeeds for each verification type you use.
- Webhook endpoint
Activeand handlingIntlVerificationUpdateandKycStatusUpdate. - SDK code calls
resumeJourneywith thetrialIdandflowIdfrom the token response.