The ChainPass API

Serious Identity Infrastructure. Simple Platform Integration.

ChainPass gives platforms verified access, user confirmation, agreements, custom requirements, and credential management through one API—or through our client dashboard.

Your platform receives the answers it needs. It never receives the identity data behind them.

One Documented Public Interface.

The public API is being built alongside the client dashboard. Every endpoint below is labelled Built, Activation Required, or Planned so platform teams can see what is ready and what comes next.

A platform can confirm that a user is real, verified, compliant, and present. It never receives a name, identity document, verified photograph, biometric record, or match percentage.
What one API does

One API. Four Core Capabilities.

01 — VERIFY

Confirm that a V.A.I. is active, compliant, and attached to the person presenting it.

02 — AUTHORIZE

Confirm access, agreements, declarations, transactions, and other platform actions through a live facial scan.

03 — ADMINISTER

Let ChainPass handle onboarding, platform requirements, verification services, and credential updates.

04 — PROVE

Maintain immutable agreement versions and verification records that cannot be rewritten after the fact.

The platform receives a decision—not a name, identity document, photograph, match score, or biometric record.
The privacy boundary

What the API Never Returns

Your platform receives verified answers without taking custody of the identity behind them.

01 — Legal name
02 — Government ID
03 — Identity document
04 — Verified photograph
05 — Biometric template
06 — Facial-match percentage
07 — Activity from another platform
08 — A session key after handoff

ChainPass separates verification from identity ownership. Your platform receives what it needs to make a decision—and nothing beneath it.

Capabilities

Start With the Answer. Open the Technology When You Need It.

Each section begins in plain language. Open any capability to view its privacy boundary, endpoints, availability, and technical behavior.

BuiltThe handler exists in the current ChainPass build.
Activation requiredThe handler is built; a production service or public route still must be connected.
PlannedApproved for the public API and documented ahead of release.

One Call at the Door

When a user arrives, the platform submits its API key and the user’s V.A.I. ChainPass returns the action required: grant access, complete enrollment, confirm first-visit terms, or reject the credential.

The platform sendsIts API key and the user’s V.A.I.
The platform receivesA clear instruction for what happens next.
The platform never receivesThe user’s name, identity document, photograph, or verification score.
Technical endpoints
POST/v1/gateActivation required
POST/v1/gate/signActivation required
POST /v1/gatePlatform key plus a V.A.I. Returns granted, no_match, enroll_required with a signed enrollment token, or terms_required.
POST /v1/gate/signThe first-visit terms signing. The platform displays its terms, the camera opens, the face is matched against the verified photo on file, an agreement row and a proof row are written, the visit is recorded, entry is granted.
Every callWrites a verification ledger row. Eligible billable results consume platform capacity. The platform never receives a name, identity document, verified photograph, biometric record, or match percentage.

A Decision Without the Identity Data

The platform sends a V.A.I. number with a live image. Once facial comparison is activated, ChainPass compares it with the verified photo on file and returns a clear decision without releasing the photo or score.

The platform sendsA V.A.I. number and a live image.
The platform receivesA clear verification result.
The platform never receivesThe verified photograph, biometric calculation, or match percentage.
Technical endpoints
POST/v1/verifyActivation required
POST/v1/photo-matchPlanned

ChainPass returns a decision, not a score. The platform never has to interpret a facial-recognition percentage.

GreenPass.
YellowBelow green. Close, not confident.
RedNot this person. Red is what triggers the manual path.
ThresholdsGlobal, set in ChainPass administration, and adjustable without a deployment. The arithmetic never leaves ChainPass.

Verified Agreements That Cannot Be Rewritten

The planned public agreement API will let platforms and V.A.I. users enter agreements, declarations, transactions, and authorizations confirmed through a facial scan.

ChainPass preserves the exact document version and its verification record. Once confirmed, neither the platform nor ChainPass can alter what was agreed.

The platform sendsThe agreement, participating V.A.I. numbers, and the required confirmation request.
The platform receivesLasting proof tied to the exact agreement version.
The platform never receivesThe user’s identity or biometric data.

The signature agreement does not require a user to approve any action. It establishes how actions they choose to confirm are authenticated and recorded.

Technical endpoints
POST/v1/agreementsPlanned
POST/v1/agreements/{id}/verifyPlanned
GET/v1/agreements/{id}/proofPlanned
GET/v1/agreements/{id}/versionsPlanned
POST/v1/agreements/documentsPlanned
01A published version is never edited or overwritten.
02Every participating V.A.I. is attached to the exact version it reviewed.
03Publishing a new version cannot change a previous agreement.
04Open agreements expire according to their defined time limit.
05No platform user or ChainPass administrator can alter a confirmed version.
Proof has value only when the underlying document cannot be rewritten. ChainPass preserves both.

Your Rules. Administered by ChainPass.

The launch V.A.I. supports the platform requirements ChainPass agrees to administer. These may include declarations, background screening, platform terms, age-verification releases, or custom agreements.

When a verified user arrives without one of your requirements, ChainPass routes the user to complete it before the handoff—at no cost to the user or platform.

If the capability does not already exist, ChainPass will build it for your platform at no cost.

The platform sendsIts selected requirements and configuration.
The platform receivesConfirmation that the user satisfies its requirements.
The platform never receivesDetails about requirements completed for another platform.
Technical endpoints
GET/v1/requirementsPlanned
PUT/v1/requirementsPlanned
GET/v1/requirements/checkPlanned
GET/v1/servicesPlanned
PUT/v1/servicesPlanned
Your platform sets the requirement. ChainPass administers it.

Requirements are configurable, allowing platforms to update onboarding without rebuilding their integration.

CatalogueEvery external service is an adapter behind one interface. Platforms elect services at onboarding through GET /v1/services and PUT /v1/services, and the adapter normalizes every engine’s output into a single documented shape.
Background screeningThe real identity goes to the supplier outside ChainPass. What comes back is binary: clear, or something on file. No detail, no record, no score. The check runs while the session is open, before the V.A.I. is minted.
Something on fileReturned as a color: #FBBF24. No badge, no label, no words.
Law-enforcement declaredReturned as a color: #F94E00. The user’s own statement, signed under penalty of perjury. Nothing verifies it, and nobody is excluded.
What is never claimedChainPass never claims a check that did not run, and does not judge conduct. The platform decides what a result means.

One Credential. Clear Answers.

Platforms can confirm whether a V.A.I. is active and whether it meets the required service level. ChainPass returns only the answer needed for the platform’s decision—never the private reason behind a credential’s status.

The platform sendsIts API key and the V.A.I. number.
The platform receivesActive or Not Active, plus the credential level when required.
The platform never receivesPrivate account history or the reason for inactivity.
Technical endpoints
GET/v1/credentials/{vai}Planned
GET/v1/credentials/{vai}/levelPlanned
POST/v1/deferralPlanned
Why Not ActiveOne answer covers a lapsed deferral, an expiry, a suspension, and a ban. A credential status is a fact about the credential; the platform is told nothing about the user.
Credential levelWhat the user holds. Entry is one comparison against the platform’s required level.
DeferralOffered per the platform’s agreement. Once, ever, per user — not per platform, not per year. Deferral is a state on the credential, visible to both parties.
RenewalGood for one calendar year. Renewed in-house against the verified photo on file where the document and the provider retention window are both still live; a fresh provider run otherwise. Both paths accrue to the originator.

Everything Your Platform Needs to Operate

The planned operations API will give each platform access to its own traffic, usage, agreements, proofs, requirements, configuration, commissions, and system health.

Operations endpoints are designed to be scoped to the platform’s API key so a platform can see only its own activity.

Traffic and usage
GET/v1/trafficPlanned
GET/v1/blocksPlanned
Agreements and proofs
GET/v1/agreementsPlanned
GET/v1/proofsPlanned
Requirements and configuration
GET/v1/configPlanned
Commissions
GET/v1/commissionsPlanned
GET/v1/commissions/{id}Planned
API-key management
POST/v1/keysPlanned
System health
GET/v1/healthBuilt
OriginationThe platform whose API key was on the enrollment call. It is written at issue by a database trigger, never by application code, and it never changes.
The three railsThe user pays for the credential. The platform pays for verifications on its own gate. ChainPass pays the originating platform.
What origination is notA first visit is not origination. Direct signups at chainpass.io have no originator.
PayoutsPayouts do not run through ChainPass. It holds only a recipient reference — ChainPass never joins a V.A.I. to a legal identity.
Secure system flow

Enrollment In. Verified Handoff Out.

The platform opens a secure ChainPass enrollment session. ChainPass administers verification, agreements, and platform requirements, then completes a server-to-server handoff.

The current handoff contains the V.A.I., the one-time session key, completion status, and the affirmed terms reference. It never contains the user’s legal name, government ID, or verified photograph.

After the handoff succeeds, ChainPass deletes its copy of the session key. It cannot be retrieved through an endpoint or resent later.

01 — PLATFORMOpens a signed enrollment session
02 — CHAINPASSAdministers verification, agreements, and platform requirements
03 — SECURE HANDOFFReturns the V.A.I., one-time session key, completion status, and terms reference
04 — COMPLETEChainPass deletes its copy of the session key

ChainPass returns the minimum handoff record the platform needs. ChainPass identity data never crosses the boundary.

ChainPass offers an optional vault module that platforms deploy within their own infrastructure. It protects session keys in a separate encrypted store without placing them beside V.A.I. numbers in the platform’s primary system.

View Vault Architecture
Technical endpoints
PUT/vault/{tag}Planned
GET/vault/{tag}Planned
Blind tagThe tag is HMAC(platform_secret, V.A.I.). The secret lives in the platform’s runtime, not in the vault store.
RecoveryA breach of the primary database yields V.A.I. numbers and no keys. The vault store alone is noise.
Full index

Every Endpoint. One Searchable List.

Search or filter the complete ChainPass API. Built endpoints have implemented handlers. Activation Required endpoints need a production dependency or public route. Planned endpoints are documented ahead of release.

API version v1 Last updated 8 September 2026
Status
Capability
Build with ChainPass

Identity Infrastructure Without the Identity Liability.

Use the ChainPass API or our client dashboard to add verified access, user confirmation, agreements, and custom platform requirements without taking custody of personal identity data. The endpoint status table shows which integrations are built and which are planned.

There are no integration or platform fees. The V.A.I. holder pays.

Start Your Integration Read the Documentation Talk to ChainPass
ChainPass
Verified person. No platform-held identity file.
Product
Home Features API FAQ Get a V.A.I.
Legal
Request terms Request privacy policy Request security materials
Contact
platforms@chainpass.io support@chainpass.io Contact us
© 2026 ChainPass. All rights reserved. Patent pending