For the complete documentation index, see llms.txt. This page is also available as Markdown.

SDK Response

Reference for the SDK response JWT. Learn payload fields, signature validation, and result checks.

JWT & Signing

A JSON Web Token (JWT) is a compact, secure standard for transmitting information between a client and a server as a JSON object.

Response parameters

The SDK returns the verification result as a JWT. To guarantee data integrity, Certta signs the JWT on the backend using a secure private key. Your backend must validate this signature before trusting the payload.

To learn more about security and secret keys, see the Authentication page:

Authentication

JWT payload example

A JWT has three parts: header, payload, and signature. The claims below are part of the payload.

{
  "header": {
    "alg": "HS256",
    "typ": "JWT"
  },
  "payload": {
    "sessionId": "01KVGG0CR3928MQERDX8NGA8AEQ",
    "personId": "user-id",
    "isAlive": false,
    "isMatch": false,
    "imageUrl": "https://mobile-prod-liveness-attempts.s3.us-east-1.amazonaws.com/...",
    "createdAt": "2026-06-19T17:49:15.432Z",
    "iat": 1781895533
  },
  "signature": "LNFjtTO27Z5GLR8NhhziX3nE8kftoemUOfkICkk5w8Q"
}
response
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzZXNzaW9uSWQiOiIwMUtWR0cwQ1IzOTI4TVFFUkRYOE5HQThaUSIsInBlcnNvbklkIjoidXNlci1pZCIsImlzQWxpdmUiOmZhbHNlLCJpbWFnZVVybCI6Imh0dHBzOi8vbW9iaWxlLXByb2QtbGl2ZW5lc3MtYXR0ZW1wdHMuczMudXMtZWFzdC0xLmFtYXpvbmF3cy5jb20vZTFjYWVkNDYtOGJlYS00ZDI0LWE4ZDQtNjVmOWMyOWI2NTcyL25vdF9pZGVudGlmaWVkL2xpdmVuZXNzL2F0dGVtcHRfMDFLVkdHME1GN1o4SzRHN1g3RzUyTVNDWkUucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNvbnRlbnQtU2hhMjU2PVVOU0lHTkVELVBBWUxPQUQmWC1BbXotQ3JlZGVudGlhbD1BS0lBUzZGMlhQQTdTRE5aQUVESyUyRjIwMjYwNjE5JTJGdXMtZWFzdC0xJTJGczMlMkZhd3M0X3JlcXVlc3QmWC1BbXotRGF0ZT0yMDI2MDYxOVQxNzQ5MTVaJlgtQW16LUV4cGlyZXM9MjU5MjAwJlgtQW16LVNpZ25hdHVyZT1lNWU1M2UyZTdiMmU0Y2Q5MTUxM2I4ZjFkZTc3YzIzYjYzN2NhMzcyNjQ1YjllNmE2ODVhNGVjNzA4ZmJhZGQxJlgtQW16LVNpZ25lZEhlYWRlcnM9aG9zdCZ4LWFtei1jaGVja3N1bS1tb2RlPUVOQUJMRUQmeC1pZD1HZXRPYmplY3QiLCJjcmVhdGVkQXQiOiIyMDI2LTA2LTE5VDE3OjQ5OjE1LjQzMloiLCJzaWduYWxzIjp7fSwiaWF0IjoxNzgxODkxMzU1fQ.LNFjtTO27Z5GLR8NhhziX3nE8kftoemUOfkICkk5w8Q
Field
Description

sessionId

Request identifier.

personId

User identifier provided for the SDK.

isAlive

Indicates whether the SDK verified a live person successfully.

isMatch

Indicates whether face match succeeded. Present when face match is enabled.

imageUrl

Temporary image URL generated by the API.

createdAt

Time when the token was created.

iat

Time when the token was issued.

message

Result message returned by the service. May be present depending on the flow.

Last updated