The IVQA Extension API is the REST interface behind the IVQA add-ons for Google Workspace and Microsoft Office. Your own tools can use it too. All verification, credential, QR and analytics logic lives in IVQA: the API is a thin, account-bound layer over the same rules the dashboard applies.
Base URL and format#
https://api.ivqa.org/api/ext
- Requests and responses are JSON.
- Every successful response contains
"ok": true; errors contain"ok": false, anerrormessage and acode. See Errors and rate limits. - Authentication is a bearer token bound to one IVQA account. See Authentication and API tokens.
What the API does#
| Area | Endpoints | Guide |
|---|---|---|
| Identity and settings | GET /ping, /profile, /organization, /settings | Documents and directory |
| Analytics | GET /dashboard, /statistics, /activity | Documents and directory |
| Directory and documents | GET /students, /employees, /documents, /documents/{family}, /search | Documents and directory |
| Verification | POST /verification, GET /verification/status, `GET | POST /qr, POST /metadata` |
| Issuance | POST /student-documents, /employee-documents, /company-documents, /institution-documents, /diploma-certificates | Issuing documents |
What the API does not do#
- File upload and PDF generation stay in the dashboard. The API returns document content and verification data for insertion into an editor; it does not produce PDFs.
- Revocation and restoration stay in the dashboard (Status & Revocations).
- A token is bound to a single organization; there is no cross-account access.
- There are no webhooks today. See Webhooks.
The rule every issuance follows#
Every issuance made through the API is a new issuance: a new document, credential, public ID, QR code and verification URL. Nothing is reused or resumed — see Issuing documents.
Machine-readable contract#
The complete contract is maintained by IVQA as an OpenAPI 3.1 document (IVQA Extension API, version 1.0.0). Ask support for the current file if you generate a client SDK.