To begin using the Age Verification Service, a session must first be created. The session ID from the Yoti session create response will be used to construct the user view URL. Result of the session can then be retrieved from webhook or the Get Session Result API.

Server
https://age.yoti.com

Age Verification Service

Server Variables

Bearer token authorization using API Key obtained from the Yoti Hub as token

Session creation

Create a session that can be used by a consumer, when a session is created, a reference ID can be provided to help you identify your customers.

Auth
Headers
Content-Typestring

Define the expected payload content type (always application/json).

Yoti-Sdk-Idstring

SDK ID obtained from the Yoti Hub

pattern: [a-zA-Z0-9\_\-]{14,40}

Request Body

This payload will generate a session configuration object

objectobject
typestring

Session type

Enum: AGE,OVER,UNDER

Default: OVER

age_estimation6 fieldsobject
digital_id6 fieldsobject
doc_scan9 fieldsobject
credit_cardobject
allowedboolean

Flag indicating the verification method is allowed

Default: true

mobileobject
allowedboolean

Flag indicating the verification method is allowed

Default: true

yoti_keyobject
allowedboolean

Flag indicating the verification method is allowed

Default: true

authenticationboolean

when authentication is set to true, users are required to use their Yoti key before they can complete the session with an age token

electronic_id5 fieldsobject
la_wallet4 fieldsobject
social_security_number4 fieldsobject
us_florida_hb34 fieldsobject
emailobject
allowedboolean

Flag indicating the verification method is allowed

Default: true

singpass4 fieldsobject
cpf4 fieldsobject
ttlinteger

Define how long the session is valid for. The user will need to complete the session before the ttl expires.

multipleOf: 1

maximum: 2592000

minimum: 60

reference_idstring

Reference ID is an optional string. Yoti returns this same string in the session result. We recommend that you do not include any personal information in this string.

callbackobject

Callback object to describe where and how a user's experienced should be managed after they have submitted age verification evidence

urlstring

The URL to redirect your user to after they complete age verification. The sessionId will be appended as a query parameter.

autoboolean

Setting auto to true will automatically redirect users after verification.

notification_urlstring

A https endpoint to call after a final result has been generated. This will be a post message containing the result and referenced_id

pattern: ^https:.*

block_biometric_consentboolean

Determine if the UI should block the display of a biometric required flow

Default: false

rule_idstring

The id in of the rule the age token must satisfy. Should be a uuid.

pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

cancel_urlstring

URL where end users get redirected when they decide to cancel current AVS session

privacy_policystring

URL for privacy policy

terms_and_conditionsstring

URL for terms and conditions

retry_enabledboolean

Ability for the user to retry verifying their age if an attempt fails

Default: false

resume_enabledboolean

Should a user be allowed to retry after a fail / error status

Default: false

blocked_locationsarray[string]

A list of locations that have been blocked for access

target_origin_urlstring

A http url that specifies the i-frame parent in order to dispatch status update event

pattern: ^http[s]?:.*

synchronous_checksboolean

If set to true, ensures that all methods have a result ready before the user is redirected to the callback URL. Default is false, this primarily affects document checks and credit card checks as these are async.

Default: false

account_idstring

An identifier external to age.yoti.com that allows a client to distiniguish between different accounts under the same sdk id

maxLength: 100

double_blindboolean

Apply a secondary anonymisation step using Digital ID/Yoti Key

Default: false

POST /api/v1/sessions
curl --request POST \
--url 'https://age.yoti.com/api/v1/sessions' \
--header 'Content-Type: application/json' \
--header 'Yoti-Sdk-Id: e8468a54-a655-47ed-92d5-ef00dcba0ac3' \
--header 'Authorization: Bearer {token}' \
--data '{
"type": "{string}",
"age_estimation": {
"allowed": true,
"threshold": 21,
"retry_enabled": false,
"retry_limit": 2,
"level": "PASSIVE",
"authenticity": "AUTO"
},
"digital_id": {
"allowed": true,
"threshold": 18,
"age_estimation_allowed": true,
"age_estimation_threshold": 21,
"retry_enabled": false,
"retry_limit": 2
},
"doc_scan": {
"allowed": true,
"threshold": 18,
"retry_enabled": false,
"retry_limit": 2,
"level": "PASSIVE",
"authenticity": "AUTO",
"preset_issuing_country": "GBR",
"disable_mobile_hand_off": false,
"synchronous_checks": false
},
"credit_card": {
"allowed": true
},
"mobile": {
"allowed": true
},
"yoti_key": {
"allowed": true,
"authentication": true
},
"electronic_id": {
"allowed": true,
"threshold": 18,
"retry_enabled": true,
"retry_limit": 2,
"sub_methods": [
"MIT_ID",
"SWEDISH_BANK_ID",
"FTN"
]
},
"la_wallet": {
"allowed": true,
"threshold": 21,
"retry_enabled": false,
"retry_limit": 2
},
"social_security_number": {
"allowed": true,
"threshold": 21,
"retry_enabled": false,
"retry_limit": 2
},
"us_florida_hb3": {
"allowed": true,
"threshold": 21,
"retry_enabled": false,
"retry_limit": 2
},
"email": {
"allowed": true
},
"singpass": {
"allowed": true,
"threshold": 21,
"retry_enabled": false,
"retry_limit": 2
},
"cpf": {
"allowed": true,
"threshold": 21,
"retry_enabled": false,
"retry_limit": 2
},
"ttl": 900,
"reference_id": "{string}",
"callback": {
"url": "https://yoti.com/success",
"auto": true
},
"notification_url": "https://notification-web-hook.yoti.com",
"block_biometric_consent": false,
"rule_id": "d1234a54-a655-47ed-92d5-ef00dcba0ac3",
"cancel_url": "https://yoti.com/cancel",
"privacy_policy": "https://www.yoti.com/privacy/",
"terms_and_conditions": "https://www.yoti.com/terms/",
"retry_enabled": false,
"resume_enabled": false,
"blocked_locations": [
"GBR",
"DEU"
],
"target_origin_url": "{string}",
"synchronous_checks": false,
"account_id": "{string}",
"double_blind": false
}'
Copy
Responses
200

OK

objectobject

Response from a session creation request

idstring

Auto-generated

expires_atdate-time

Session expiry time

400

Bad request - missing field, spoofing attempt detected, invalid validation methods, need to re-verify

401

Missing or unknown Yoti-Sdk-Id

403

Not allowed to use this session

Response
{
"id": "d1234a54-a655-47ed-92d5-ef00dcba0ac3",
"expires_at": "2026-05-02T11:53:33Z"
}
Copy

Session retrieval

Retrieve the configuration setup for a session.

Auth
Headers
Yoti-Sdk-Idstring

SDK ID obtained from the Yoti Hub

pattern: [a-zA-Z0-9\_\-]{14,40}

Path Params
sessionIdstring

The consumer's session id, created by the Yoti server.

pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

GET /api/v1/sessions/{sessionId}
curl --get \
--url 'https://age.yoti.com/api/v1/sessions/def6fd14-dba9-4610-b6c3-9a7e8909aac0' \
--header 'Yoti-Sdk-Id: e8468a54-a655-47ed-92d5-ef00dcba0ac3' \
--header 'Authorization: Bearer {token}'
Copy
Responses
200

Session retrieved for client consumption

objectobject
idstring

Session ID created by Yoti server

sdk_idstring

SDK ID obtained from the Yoti Hub

callbackobject

Callback object to describe how a user's experience should be managed after they have submitted age verification evidence

autoboolean

Setting auto to true will automatically redirect users after verification.

typestring

Session type

Enum: AGE,OVER,UNDER

Default: OVER

statusstring

only sessions with a status of PENDING and which are not expired are returned at the moment

Enum: PENDING,COMPLETE,PROCESSING,ERROR,FAIL,CANCELLED,IN_PROGRESS

expires_atdate-time

Session expiry time

biometric_consent_requiredboolean

Determine whether the Biometric Consent Screen is enabled

Default: true

retry_enabledboolean

Ability for the user to retry verifying their age if an attempt fails

Default: false

resume_enabledboolean

This allows the user to resume a session (if the link is re-accessed).

Default: false

notification_urlstring

A https endpoint to call after a final result has been generated. This will be a post message containing the result and reference_id

pattern: ^https:.*

cancel_urlstring

URL where end users get redirected when they decide to cancel current AVS session

reference_idstring

Reference ID is an optional string. Yoti returns this same string in the session result. We recommend that you do not include any personal information in this string.

created_atdate-time

Session creation time

rule_idstring

This allows an age token rule ID to be specified. If a user has previously passed a session and did so by meeting the age threshold configured in your rule, the user will automatically redirect to the callback.

pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

blocked_locationsarray[string]

A list of locations that have been blocked for access

updated_atdate-time

Session update time

biometric_consent_given_atdate-time

The time when the biometric consent was given

target_origin_urlstring

A http url that specifies the i-frame parent in order to dispatch status update event

pattern: ^http[s]?:.*

synchronous_checksboolean

If set to true, ensures that all methods have a result ready before the user is redirected to the callback URL. Default is false, this primarily affects document checks and credit card checks as these are async.

Default: false

double_blindboolean

Apply a secondary anonymisation step using Digital ID/Yoti Key

Default: false

404

Session not found

410

Session has expired for current check or invalid status

Response
{
"id": "e3746a54-a655-47ed-92d5-ef00dcba0ac3",
"sdk_id": "d2233a54-a655-47ed-92d5-ef00dcba0ac3",
"callback": {
"auto": true
},
"type": "OVER",
"status": "PENDING",
"expires_at": "2026-05-02T11:53:33Z",
"biometric_consent_required": true,
"retry_enabled": false,
"resume_enabled": false,
"notification_url": "https://notification-web-hook.yoti.com",
"cancel_url": "https://yoti.com/cancel",
"reference_id": "user001",
"created_at": "2026-05-02T11:53:33Z",
"rule_id": "d1234a54-a655-47ed-92d5-ef00dcba0ac3",
"blocked_locations": [
"GBR",
"DEU"
],
"updated_at": "2026-05-02T11:53:33Z",
"biometric_consent_given_at": "2026-05-02T11:53:33Z",
"target_origin_url": "{string}",
"synchronous_checks": false,
"double_blind": false
}
Copy

Get the session result

Auth
Headers
Yoti-Sdk-Idstring

SDK ID obtained from the Yoti Hub

pattern: [a-zA-Z0-9\_\-]{14,40}

Path Params
sessionIdstring

The consumer's session id, created by the Yoti server.

pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

GET /api/v1/sessions/{sessionId}/result
curl --get \
--url 'https://age.yoti.com/api/v1/sessions/def6fd14-dba9-4610-b6c3-9a7e8909aac0/result' \
--header 'Yoti-Sdk-Id: e8468a54-a655-47ed-92d5-ef00dcba0ac3' \
--header 'Authorization: Bearer {token}'
Copy
Responses
200

Session retrieved for relying party consumption

objectobject
idstring

Session ID created by Yoti server

sdk_idstring

SDK ID obtained from the Yoti Hub

callbackobject

Callback object to describe how a user's experience should be managed after they have submitted age verification evidence

autoboolean

Setting auto to true will automatically redirect users after verification.

typestring

Session type

Enum: AGE,OVER,UNDER

Default: OVER

statusstring

only sessions with a status of PENDING and which are not expired are returned at the moment

Enum: PENDING,COMPLETE,PROCESSING,ERROR,FAIL,CANCELLED,IN_PROGRESS

expires_atdate-time

Session expiry time

biometric_consent_requiredboolean

Determine whether the Biometric Consent Screen is enabled

Default: true

retry_enabledboolean

Ability for the user to retry verifying their age if an attempt fails

Default: false

resume_enabledboolean

This allows the user to resume a session (if the link is re-accessed).

Default: false

notification_urlstring

A https endpoint to call after a final result has been generated. This will be a post message containing the result and reference_id

pattern: ^https:.*

cancel_urlstring

URL where end users get redirected when they decide to cancel current AVS session

reference_idstring

Reference ID is an optional string. Yoti returns this same string in the session result. We recommend that you do not include any personal information in this string.

created_atdate-time

Session creation time

rule_idstring

This allows an age token rule ID to be specified. If a user has previously passed a session and did so by meeting the age threshold configured in your rule, the user will automatically redirect to the callback.

pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

blocked_locationsarray[string]

A list of locations that have been blocked for access

updated_atdate-time

Session update time

biometric_consent_given_atdate-time

The time when the biometric consent was given

target_origin_urlstring

A http url that specifies the i-frame parent in order to dispatch status update event

pattern: ^http[s]?:.*

synchronous_checksboolean

If set to true, ensures that all methods have a result ready before the user is redirected to the callback URL. Default is false, this primarily affects document checks and credit card checks as these are async.

Default: false

double_blindboolean

Apply a secondary anonymisation step using Digital ID/Yoti Key

Default: false

401

Missing or unknown Yoti-Sdk-Id

404

Session not found

Response
{
"id": "e3746a54-a655-47ed-92d5-ef00dcba0ac3",
"sdk_id": "d2233a54-a655-47ed-92d5-ef00dcba0ac3",
"callback": {
"auto": true
},
"type": "OVER",
"status": "PENDING",
"expires_at": "2026-05-02T11:53:33Z",
"biometric_consent_required": true,
"retry_enabled": false,
"resume_enabled": false,
"notification_url": "https://notification-web-hook.yoti.com",
"cancel_url": "https://yoti.com/cancel",
"reference_id": "user001",
"created_at": "2026-05-02T11:53:33Z",
"rule_id": "d1234a54-a655-47ed-92d5-ef00dcba0ac3",
"blocked_locations": [
"GBR",
"DEU"
],
"updated_at": "2026-05-02T11:53:33Z",
"biometric_consent_given_at": "2026-05-02T11:53:33Z",
"target_origin_url": "{string}",
"synchronous_checks": false,
"double_blind": false
}
Copy