All endpoints below are GET requests relative to https://api.ivqa.org/api/ext and require scope credentials:read unless noted.
Identity and settings (no scope required)#
| Endpoint | Returns |
|---|---|
GET /ping | The token's account id and scopes — the quickest way to validate a token |
GET /profile | The token-bound identity and its permissions |
GET /organization | The organization the token is bound to |
GET /settings | Effective, server-computed client settings: organization, scopes, permitted document families, feature flags and limits (rate limit, max page size 100). POST /settings echoes accepted client preferences; they are not persisted in v1. |
Analytics#
| Endpoint | Parameters | Returns |
|---|---|---|
GET /dashboard | — | Integration overview, document statistics and 30-day KPIs |
GET /statistics | from, to, granularity, doc_type (default all) | Verification KPIs and time series for the range |
GET /activity | limit (1–200, default 50) | Recent integration activity, privacy-preserving |
Documents#
GET /documents lists the documents of the families the caller may read; GET /documents/{family} restricts to one family.
| Workspace | Readable families |
|---|---|
Institution (ecole) | school (student documents), org (institution documents), certificates |
Company (entreprise) | employee, company |
| Either | editor (verifications created for external editor files) |
Only documents that have a generated credential appear; portal drafts do not.
Directories#
GET /students (institution workspaces)#
Requires the view students permission. Parameters: q (matches UID, first name, last name or email), status (pending, validated, revoked), page, per_page (1–100, default 25).
{
"ok": true,
"items": [{ "student_uid": "STU-2026-0001", "name": "Amina B.", "status": "validated" }],
"pagination": { "page": 1, "per_page": 25, "total": 1, "total_pages": 1 }
}
The selection identity is the student UID; numeric database ids are not returned. Company workspaces get 403 forbidden.
GET /employees (company workspaces)#
Requires the view employees permission. Parameters: q, status (active, inactive, pending, validated, revoked), page, per_page (max 100). Items carry employee_uid, name, department, position and status. Institution workspaces get 403 forbidden.
Search#
GET /search?q=…&limit=25 (max 100) searches documents by title or public ID within the permitted families:
{ "ok": true, "query": "diplome", "items": [{ "public_id": "IVQA-CER-2026-3QF7…", "type": "certificate", "family": "certificates", "title": "Diplôme 2026", "status": "valid", "verify_url": "https://…" }], "count": 1 }
Pagination and validation#
Invalid page or per_page values return 422 invalid_request. Results are always limited to the token's own account.