These POST endpoints are what the add-ons call when a user selects Generate. They create the document's identity in IVQA and return host-neutral content for the editor to insert, together with the credential and QR data. All require scope verify:write.
The always-new rule#
Every call creates a new issuance: a new document, a new credential, a new public ID, a new QR code and a new verification URL. The API never reuses an existing issuance, never resumes a dashboard draft and never targets an existing document. Calling Generate twice for the same person and type produces two documents with two different public IDs. reference.reused is therefore always false.
POST /student-documents (institution workspaces)#
Requires an institution workspace and the manage documents permission.
{ "student_uid": "STU-001", "document_type": "attestation_scolarite", "target": "google_docs", "locale": "fr" }
| Field | Values |
|---|---|
student_uid | The student's UID (the student must be validated) |
document_type | attestation_scolarite, attestation_reussite, releve_notes, certificat_stage, lettre_recommandation |
target | google_docs, google_sheets, google_slides, office_word, office_excel, office_powerpoint — a presentation hint for the host; it never changes the issuance |
locale | fr or en |
expiry_date | Optional YYYY-MM-DD; when omitted the API issuance has no expiry (the dashboard's 3-month rule applies to dashboard issuances only) |
Response: content (version student-document-content/v1), credential (public_id, status), verify_url, qr.payload, title and reference.reused: false. No internal ids or storage paths are returned.
Errors: student_not_found, student_not_validated, invalid_type, plus the generic codes.
POST /employee-documents (company workspaces)#
Requires a company workspace and the manage documents permission.
{ "employee_uid": "EMP-001", "document_type": "work_certificate", "target": "office_word", "locale": "en" }
| Field | Values |
|---|---|
employee_uid | The employee's UID |
document_type | work_certificate, salary_certificate, leave_certificate, mission_order, termination_certificate |
target | Same six values as above |
locale | fr or en (defaults to the account's language) |
doc_title, recipient_name, notes | Optional text fields |
Response: the exact employee-document-content/v1 payload plus credential.status (valid) and reference.reused: false. Unsupported request fields are rejected with 422 invalid_request.
Other issuance endpoints#
POST /company-documents, POST /institution-documents (a named organization document, document_name, optional expiry_date) and POST /diploma-certificates (a student's award) follow the same envelope. Their exact request shapes are in the OpenAPI contract available from support.
Where these documents appear#
Documents issued through the API carry their own public IDs and verify on check.ivqa.org like any other. They are managed from Status & Revocations (revoke / restore) but are not listed in the dashboard's Student documents or Employee documents panels, which are reserved for documents created there.