On this page
startIdentityVerification
mutation · in the family Your own session
What it does
Begin — or pick back up — your identity verification through Stripe; answers the secure Stripe page to complete it on.
Start — or re-open — the calling account's identity verification. Answers the hosted flow's short-lived url; a live attempt re-answers ITS fresh url (one attempt chain — only a canceled one re-mints). Refuses when the account holds no owner seat (CONFLICT/REF_STATE — the requirement attaches to ownership) and when already verified (CONFLICT/REF_STATE naming the forever law). SELF-scoped BY CONSTRUCTION; USER-plane only. Requires authentication.
What happens
Opens a Stripe Identity session under this account. Once verified, you are never asked again — for any organization, now or later.
Careful
Only asked of accounts that own an organization or organization group; the documents live with Stripe, never on this platform.
Who may call it
Capability area: Your own session — What every signed-in person may do for themselves — their session, their profile and their own work.
- Owner
- System Administrator
- Manager
- Associate Manager
- Warehouse Associate
- Sales Associate
- Cashier
- An API key whose scope allows
api:startIdentityVerification
Returns
IdentityVerificationStart IdentityVerificationStart! — One started (or re-opened) verification attempt: the hosted-flow door + the standing it opened against.
Example request
mutation ExampleStartIdentityVerification {
startIdentityVerification {
status
sessionRef
url
}
}
Send it with the envelope naming the version: "extensions": {"at": {"version": {"name":"genesis","number":0}}}.
Example response
{
"data": {
"startIdentityVerification": {
"status": "<status>",
"sessionRef": "<session ref>",
"url": "https://example.com/hook"
}
},
"extensions": {
"at": {
"callId": "01EXAMPLE-CALL-ID",
"version": {
"requested": {
"name": "genesis",
"number": 0
},
"serviced": {
"name": "genesis",
"number": 0
}
}
}
}
}
Errors this call can answer
VALIDATION/INVALID— Something in the request is not valid. (VALIDATION)AUTHN/REQUIRED— Sign in to do this. (AUTHN)AUTHZ/FORBIDDEN— Your role does not allow this action. (AUTHZ)RATE_LIMIT/THROTTLED— Too many requests in a short time. (RATE_LIMIT)CONFLICT/*— The record’s state, or a change made in the meantime, does not allow this; the codes are on the CONFLICT page. (CONFLICT)VALIDATION/VERSION_REQUIRED— The request did not say which app version it came from. (VALIDATION)