Skip to main content
POST

Authorizations

DPoP
string
header
required

Per-request DPoP proof JWT (RFC 9449). MUST accompany the Authorization: DPoP <access_token> header on every protected operation. The proof is signed by the merchant's private DPoP key and carries htm, htu, iat, jti, and ath claims.

Headers

Idempotency-Key
string
required

Unique key identifying this operation. Sending the same key twice returns the original response instead of creating a duplicate. Keys are retained for 24 hours.

Maximum string length: 255

Body

application/json
type
enum<string>
required
Available options:
person,
business
display_name
string
required

The subject's legal name. Vault-tokenized at rest; masked on every read.

email
string

Where the hosted link is delivered (with delivery: "email"), and the address shown in the flow. Without an email on file, delivery cannot happen — the attempt stays created and you deliver the link yourself.

external_ref
string

Optional identifier from your systems, echoed back on reads.

country
string

ISO 3166-1 alpha-2. Recommended — it feeds sanctions screening disambiguation.

delivery
enum<string>
default:manual

email — Anton emails the hosted link to the subject. manual (the default when omitted) — you deliver the returned hosted_link yourself.

Available options:
email,
manual
message
string

Optional text shown in the delivery email, attributed to your business. Used for that one send and never persisted (it may carry incidental PII) — it cannot be read back.

Maximum string length: 500

Hosted-link lifetime.

Available options:
7,
14,
30

Response

Subject created; first verification attempt opened.

data
object
required