Skip to main content
GET
Verdict endpoint
string
required
The 32-character lowercase hex request ID from the collector.
string
required
Bearer hrtc_sk_…
Call it from your backend. The secret key is tenant-scoped; keep it out of browser code. requestId is the raw 32-character lowercase hex string from the collector, unchanged. The result is ready when the collector returns ok: true. An opened session that fails to submit finalizes as refused 15 seconds after opening. Ordinary results stay readable for seven days. A zdr: true result allows one read within ten seconds, and that read destroys it.

Status codes

Keep the protected action pending or reject it when the result is unavailable.

Response

Every field is in the verdict schema.

Server clients

Use the Node, Python and PHP clients for authenticated verdict reads with timeouts, response validation and error handling. The same clients support siteverify and challenge calls.