# startIdentityVerification

mutation · in the family [Your own session](/reference/your-own-session/)

## What it does

Begin — or pick back up — your identity verification through Stripe; answers the secure Stripe page to complete it on.

Start — or re-open — the calling account's identity verification. Answers the hosted flow's short-lived url; a live attempt re-answers ITS fresh url (one attempt chain — only a canceled one re-mints). Refuses when the account holds no owner seat (CONFLICT/REF_STATE — the requirement attaches to ownership) and when already verified (CONFLICT/REF_STATE naming the forever law). SELF-scoped BY CONSTRUCTION; USER-plane only. Requires authentication.

## What happens

Opens a Stripe Identity session under this account. Once verified, you are never asked again — for any organization, now or later.

## Careful

Only asked of accounts that own an organization or organization group; the documents live with Stripe, never on this platform.

## Who may call it

Capability area: **Your own session** — What every signed-in person may do for themselves — their session, their profile and their own work.

- Owner
- System Administrator
- Manager
- Associate Manager
- Warehouse Associate
- Sales Associate
- Cashier
- An API key whose scope allows `api:startIdentityVerification`

## Returns

[IdentityVerificationStart](/types/IdentityVerificationStart/) `IdentityVerificationStart!` — One started (or re-opened) verification attempt: the hosted-flow door + the standing it opened against.

## Example request

```graphql
mutation ExampleStartIdentityVerification {
  startIdentityVerification {
    status
    sessionRef
    url
  }
}
```

Send it with the envelope naming the version: `"extensions": {"at": {"version": {"name":"genesis","number":0}}}`.

## Example response

```json
{
  "data": {
    "startIdentityVerification": {
      "status": "<status>",
      "sessionRef": "<session ref>",
      "url": "https://example.com/hook"
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": {
          "name": "genesis",
          "number": 0
        },
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

## Errors this call can answer

- `VALIDATION/INVALID` — Something in the request is not valid. ([VALIDATION](/errors/VALIDATION/))
- `AUTHN/REQUIRED` — Sign in to do this. ([AUTHN](/errors/AUTHN/))
- `AUTHZ/FORBIDDEN` — Your role does not allow this action. ([AUTHZ](/errors/AUTHZ/))
- `RATE_LIMIT/THROTTLED` — Too many requests in a short time. ([RATE_LIMIT](/errors/RATE_LIMIT/))
- `CONFLICT/*` — The record’s state, or a change made in the meantime, does not allow this; the codes are on the CONFLICT page. ([CONFLICT](/errors/CONFLICT/))
- `VALIDATION/VERSION_REQUIRED` — The request did not say which app version it came from. ([VALIDATION](/errors/VALIDATION/))

## Used in

- [Verify your identity as an owner](/use-cases/verify-your-identity-as-an-owner/)
