Answer one text step of the capture spec
Submit the answer to a TEXT step of the verification’s steps. Same trust model as /captures: the path’s token is the credential.
The server validates value against the step’s declared validation (length bounds + format — numeric_id digits only, alphanumeric_id letters/digits/hyphens). Re-submitting overwrites the previous answer while the verification is still open; terminal statuses reject with answers_closed.
Completion: a verification completes once every image step is at its max AND every required text step is answered. When this answer is the last missing piece, the analysis pipeline runs without any further action.
Provenance: answers are USER-DECLARED (typed by the person capturing), never sensor-attested like the photos — see RecordSeal.answers_provenance.
Returns: the updated verification snapshot (post-write state), including answers and record_seal.
Authorizations
Possession of the verification id in the URL path (/v1/verifications/:token/...) authenticates the SPA capture flow. No header — the id is the credential. ULIDs are large enough that existence-by-id is not a meaningful leak. Used for POST /captures/upload-url, POST /captures, GET /v1/verify/:token.
Path Parameters
^vfy_[0-9A-HJKMNP-TV-Z]{26}$"vfy_01HXYZABCDEFGHJKMNPQRSTVWX"
Body
Response
Answer persisted. Returns the updated verification.
Canonical wire shape for a verification. narrative is present only after POST /v1/verifications/:id/finalize ran. verdict is present only after analysis completed. case_analysis is the structured Gemini multi-image rubric, embedded inline by the sync finalize path when analysis succeeded.
^vfy_[0-9A-HJKMNP-TV-Z]{26}$Lifecycle state. pending → first capture flips to partially_captured → analysis sets the verdict and transitions to completed. Terminal: completed, expired, failed. abandoned is a side-branch off pending/partially_captured, reported by the capture screen via POST /v1/verifications/:token/progress when the end user leaves before finishing — NOT terminal: a later capture resurrects the row to partially_captured like any other.
pending, partially_captured, completed, expired, failed, abandoned x >= 0Tenant-supplied configuration baked into the token at issue time. Immutable after creation — changing config means issuing a new verification. steps is the normalized capture spec: requests that sent max_captures: N read back as a single anonymous step { key: "capture_1", min: N, max: N }.
Integrity seal over the verification record including answers. Present only when answers exist and sealing is on (seal !== false). The hash proves the stored answers have not changed — it does NOT claim they are true or sensor-attested; answers_provenance carries that distinction explicitly.
Aggregate verdict produced by the per-capture analysis pipeline. label is the human-readable bucket; score is the confidence in the verdict.
2000Structured output from the multi-image case-analysis worker (Gemini batch reasoning). Per-dimension scores 0..1 where 0 = nothing suspicious on that dimension and 1 = that dimension alone is grounds to reject. overall_risk_score aggregates with cross-dimensional reasoning, not a simple average.
Object-check result. Present only when the verification was created with expected_object. Independent of the fraud verdict.
Condition assessment. Present only when the verification was created with condition_aspects — the free-form tenant-defined aspect names (any language, any domain). score is the one-decimal average of aspect scores; label buckets it (>=7.5 good, >=5 fair, else poor). Independent of the fraud verdict.
Latest funnel-progress snapshot reported via POST /v1/verifications/:token/progress. A snapshot, not an event log — each call overwrites the previous one. Operator-only; never present on the public projection.