Skip to main content
POST
Create Verification Token
Uploads the account holder’s identity document and returns a Sumsub WebSDK access token for the liveness check, in one call. For an individual account only. The two halves of verification are split between you and us: you send the identity document, and the SDK session you embed captures liveness. The SDK does not ask for a document, so collect it in your own UI and send it here. For related persons on business accounts, use Generate KYC Link instead — it provides a hosted page and requires no SDK integration.
The document is required. A token issued without one leaves the account holder with no identity document on file, and USD account issuance later fails because the document set is incomplete.

Document types

Send the reverse as documentBack. Omitting it for one of the two-sided types is rejected with a message naming the field. country is the 2-letter ISO code of the issuing country. Leave it out and the country on the account’s address is used.

Example Request

A two-sided document carries both faces:

Example Response

Using the token

Pass the token to the Sumsub WebSDK in your frontend. The document is already on file by this point, so the session the user sees is the liveness check:
Tokens expire after 30 minutes. Use the SDK’s expiration handler to request a fresh token from this endpoint — send the document again with it.
Poll Get Verification Status to confirm the result before submitting the application, and List Verification Documents to see what we hold for the account holder.

Authorizations

X-API-Key
string
header
required

Your Rolla API key

Path Parameters

accountId
string<uuid>
required

Identifier of an account owned by the same user as your API key's business

Body

multipart/form-data
document
file
required

The account holder's identity document, image or PDF. Front side for a two-sided document

documentBack
file

Reverse side. Required for ID_CARD, DRIVER_LICENSE and RESIDENCE_PERMIT

documentType
enum<string>
default:INTERNATIONAL_PASSPORT

Which identity document is being sent. Defaults to INTERNATIONAL_PASSPORT

Available options:
INTERNATIONAL_PASSPORT,
ID_CARD,
DRIVER_LICENSE,
RESIDENCE_PERMIT
Example:

"ID_CARD"

country
string

2-letter ISO code of the country that issued the document. Defaults to the country on the account's address

Required string length: 2
Example:

"NG"

front
file
deprecated

Alias for document

back
file
deprecated

Alias for documentBack

Response

Verification token created successfully

status
integer
required
Example:

201

message
string
required
Example:

"Verification token created successfully"

success
boolean
required
Example:

true

data
object
required