Access map
Public, workspace and device access.
Public preview
Verifier API GET requests are unauthenticated and limited to approved public preview records.
Workspace session
Private application requests use your signed in account access token and current permissions for the requested workspace. Protected tool actions also require the current identity eligibility.
Paired device
Simulator routes use a one time pairing flow followed by a device bearer token. The server stores its hash and rechecks the account’s eligibility and authority.
Public surface
Do not send secrets to the Verifier API.
/api/verifier/v1/resolve?code=<publicVerifyId_or_slug>Public record resolver
Returns approved public preview context or a generic not found response.
Access: Public, no API key
curl "https://digibridge-home-pages.vercel.app/api/verifier/v1/resolve?code=<publicVerifyId_or_slug>"Application surface
Workspace routes use a signed in user token.
Authorization: Bearer <firebase_id_token>
Content-Type: application/jsonWorkspace boundary
- Each protected request must carry a valid account token
- Current identity eligibility is a separate Sumsub requirement for protected tools
- Workspace access is checked server side on every protected route
- Viewer roles cannot use write protected operations
- Use the documented public API or agree a separate organisation interface
Device interface reference
Pair once, store the device token locally.
/api/daemon/devices/pair-codeCreate a 10 minute pairing code
Requires current identity eligibility and workspace administration for this simulator interface.
Access: Signed in account access token
/api/daemon/devices/registerRegister a simulator or development device
Consumes the workspace ID and pairing code, then returns a one time device token.
Access: Short lived pairing code
/api/daemon/proof-events/ingestSubmit a signed simulator event
Validates the paired device, canonical event hash, Ed25519 signature, replay state and previous event continuity.
Access: Device bearer token or X-DigiBridge-Device-Token
Authorization: Bearer <one_time_device_token>
# Or: X-DigiBridge-Device-Token: <one_time_device_token>Recording and analysis
A sign in token is not permission to collect more data.
Keep authority specific
- An invitation grants only its stated workspace, project or asset scope
- A public profile badge does not unlock recording or private records
- A device token must not be reused as an organisation API key
- Permission withdrawal and changed account access must be respected
Organisation integrations
Discuss service access before integration.
Confirm these in your integration agreement
- DigiBridge secret API keys
- Published rate limit headers or quotas
- Webhook signatures and retry contracts
- Usage billing or enterprise SLAs