curl --request POST \
--url https://api.botshield.ai/operations/sdk/create-verification-link \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_email": "[email protected]",
"return_url": "<string>",
"webhook_url": "<string>",
"scope": "<string>",
"mode": "linked-account",
"botshield_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"partner_user_ref": "<string>",
"link_on_verify": true,
"parent_request_id": "<string>",
"metadata": {}
}
'import requests
url = "https://api.botshield.ai/operations/sdk/create-verification-link"
payload = {
"user_email": "[email protected]",
"return_url": "<string>",
"webhook_url": "<string>",
"scope": "<string>",
"mode": "linked-account",
"botshield_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"partner_user_ref": "<string>",
"link_on_verify": True,
"parent_request_id": "<string>",
"metadata": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
user_email: '[email protected]',
return_url: '<string>',
webhook_url: '<string>',
scope: '<string>',
mode: 'linked-account',
botshield_user_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
partner_user_ref: '<string>',
link_on_verify: true,
parent_request_id: '<string>',
metadata: {}
})
};
fetch('https://api.botshield.ai/operations/sdk/create-verification-link', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.botshield.ai/operations/sdk/create-verification-link",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'user_email' => '[email protected]',
'return_url' => '<string>',
'webhook_url' => '<string>',
'scope' => '<string>',
'mode' => 'linked-account',
'botshield_user_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'partner_user_ref' => '<string>',
'link_on_verify' => true,
'parent_request_id' => '<string>',
'metadata' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.botshield.ai/operations/sdk/create-verification-link"
payload := strings.NewReader("{\n \"user_email\": \"[email protected]\",\n \"return_url\": \"<string>\",\n \"webhook_url\": \"<string>\",\n \"scope\": \"<string>\",\n \"mode\": \"linked-account\",\n \"botshield_user_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"partner_user_ref\": \"<string>\",\n \"link_on_verify\": true,\n \"parent_request_id\": \"<string>\",\n \"metadata\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.botshield.ai/operations/sdk/create-verification-link")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"user_email\": \"[email protected]\",\n \"return_url\": \"<string>\",\n \"webhook_url\": \"<string>\",\n \"scope\": \"<string>\",\n \"mode\": \"linked-account\",\n \"botshield_user_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"partner_user_ref\": \"<string>\",\n \"link_on_verify\": true,\n \"parent_request_id\": \"<string>\",\n \"metadata\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.botshield.ai/operations/sdk/create-verification-link")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"user_email\": \"[email protected]\",\n \"return_url\": \"<string>\",\n \"webhook_url\": \"<string>\",\n \"scope\": \"<string>\",\n \"mode\": \"linked-account\",\n \"botshield_user_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"partner_user_ref\": \"<string>\",\n \"link_on_verify\": true,\n \"parent_request_id\": \"<string>\",\n \"metadata\": {}\n}"
response = http.request(request)
puts response.read_body{
"data": {
"data": {
"request_id": "<string>",
"deep_link": "<string>",
"web_url": "<string>",
"qr_code_url": "<string>",
"expires_at": "2023-11-07T05:31:56Z",
"pushed_to_devices": 123,
"sdk_type": "signal",
"auth_mode": "linked-account",
"scope": "<string>",
"organization": {
"id": "<string>"
},
"gate_type": "human",
"age_threshold": 13
},
"error": {
"message": "<string>",
"statusCode": 123,
"code": "<string>",
"min_ttl_seconds": 123,
"max_ttl_seconds": 123,
"violations": [
{
"type": "<string>",
"path": "<string>",
"severity": "<string>"
}
]
}
}
}{
"message": "Invalid input provided",
"input": {},
"errors": [
{
"propertyPath": "<string>",
"invalidValue": "<unknown>",
"message": "<string>"
}
]
}{
"error": {
"message": "<string>",
"statusCode": 123
}
}Create a verification request
Creates a verification request (deep link, web URL, QR code) for a gate. Requires an grant token from create-session. Returns 409 when a pending request already exists for the same gate and user.
curl --request POST \
--url https://api.botshield.ai/operations/sdk/create-verification-link \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"user_email": "[email protected]",
"return_url": "<string>",
"webhook_url": "<string>",
"scope": "<string>",
"mode": "linked-account",
"botshield_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"partner_user_ref": "<string>",
"link_on_verify": true,
"parent_request_id": "<string>",
"metadata": {}
}
'import requests
url = "https://api.botshield.ai/operations/sdk/create-verification-link"
payload = {
"user_email": "[email protected]",
"return_url": "<string>",
"webhook_url": "<string>",
"scope": "<string>",
"mode": "linked-account",
"botshield_user_id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"partner_user_ref": "<string>",
"link_on_verify": True,
"parent_request_id": "<string>",
"metadata": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
user_email: '[email protected]',
return_url: '<string>',
webhook_url: '<string>',
scope: '<string>',
mode: 'linked-account',
botshield_user_id: '3c90c3cc-0d44-4b50-8888-8dd25736052a',
partner_user_ref: '<string>',
link_on_verify: true,
parent_request_id: '<string>',
metadata: {}
})
};
fetch('https://api.botshield.ai/operations/sdk/create-verification-link', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.botshield.ai/operations/sdk/create-verification-link",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'user_email' => '[email protected]',
'return_url' => '<string>',
'webhook_url' => '<string>',
'scope' => '<string>',
'mode' => 'linked-account',
'botshield_user_id' => '3c90c3cc-0d44-4b50-8888-8dd25736052a',
'partner_user_ref' => '<string>',
'link_on_verify' => true,
'parent_request_id' => '<string>',
'metadata' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.botshield.ai/operations/sdk/create-verification-link"
payload := strings.NewReader("{\n \"user_email\": \"[email protected]\",\n \"return_url\": \"<string>\",\n \"webhook_url\": \"<string>\",\n \"scope\": \"<string>\",\n \"mode\": \"linked-account\",\n \"botshield_user_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"partner_user_ref\": \"<string>\",\n \"link_on_verify\": true,\n \"parent_request_id\": \"<string>\",\n \"metadata\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.botshield.ai/operations/sdk/create-verification-link")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"user_email\": \"[email protected]\",\n \"return_url\": \"<string>\",\n \"webhook_url\": \"<string>\",\n \"scope\": \"<string>\",\n \"mode\": \"linked-account\",\n \"botshield_user_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"partner_user_ref\": \"<string>\",\n \"link_on_verify\": true,\n \"parent_request_id\": \"<string>\",\n \"metadata\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.botshield.ai/operations/sdk/create-verification-link")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"user_email\": \"[email protected]\",\n \"return_url\": \"<string>\",\n \"webhook_url\": \"<string>\",\n \"scope\": \"<string>\",\n \"mode\": \"linked-account\",\n \"botshield_user_id\": \"3c90c3cc-0d44-4b50-8888-8dd25736052a\",\n \"partner_user_ref\": \"<string>\",\n \"link_on_verify\": true,\n \"parent_request_id\": \"<string>\",\n \"metadata\": {}\n}"
response = http.request(request)
puts response.read_body{
"data": {
"data": {
"request_id": "<string>",
"deep_link": "<string>",
"web_url": "<string>",
"qr_code_url": "<string>",
"expires_at": "2023-11-07T05:31:56Z",
"pushed_to_devices": 123,
"sdk_type": "signal",
"auth_mode": "linked-account",
"scope": "<string>",
"organization": {
"id": "<string>"
},
"gate_type": "human",
"age_threshold": 13
},
"error": {
"message": "<string>",
"statusCode": 123,
"code": "<string>",
"min_ttl_seconds": 123,
"max_ttl_seconds": 123,
"violations": [
{
"type": "<string>",
"path": "<string>",
"severity": "<string>"
}
]
}
}
}{
"message": "Invalid input provided",
"input": {},
"errors": [
{
"propertyPath": "<string>",
"invalidValue": "<unknown>",
"message": "<string>"
}
]
}{
"error": {
"message": "<string>",
"statusCode": 123
}
}Authorizations
The single-use grant token (bss_…) returned by POST /sdk/create-session. It lives 5 minutes and is consumed by this call.
Body
Deprecated. Accepted and ignored — it is not stored.
Where the web flow returns after verification.
Reserved. Webhook endpoints are configured in the Console (Settings → Developer Tools → Webhooks), not per request.
The gate this request runs (the gate's action name, as listed in the Console under BotShield Gate).
signal, presence linked-account = OAuth+passkey, private = direct WebAuthn (no PII)
linked-account, private Returning user ID to skip onboarding
Your own reference for this user (hashed at rest, never returned). Enables BotShield ID continuity: on later visits a returning human evaluates as human_verified without a ceremony.
Write the partner_user_ref ↔ BotShield ID linkage after a successful verification. Set false as a compliance escape hatch.
The req_* id returned by the client pre-check (signal/evaluate) when this request is its presence ceremony; correlates the two events.
Response
Verification link created. NOTE: handler errors also arrive here (HTTP 200) as data.error — codes for this operation: 400 (partner not found / gate not active), 401, 403 (gate not in the token allowlist), 409 (pending request already exists — call revoke-verification).
Show child attributes
Show child attributes
