These endpoints create and read verifications — credentials attached to a document that lives in an external editor (a Google Doc, a Word file…). All URLs are relative to https://api.ivqa.org/api/ext.

POST /verification — scope verify:write#

Creates a verification for an external editor document, or returns the existing one for the same editor file.

{
  "doc_id": "1AbCdEf_googleDocFileId",
  "product": "docs",
  "title": "Attestation de travail",
  "include_qr": true,
  "external_url": "https://docs.google.com/document/d/1AbCdEf/edit"
}
  • doc_id is the external editor file id, not an IVQA id. When omitted, IVQA derives the Google file id from external_url; it never invents one.
  • Employee-bound verification (company workspaces): add family: "employee", the employee_id, a doc_type such as work_certificate, and optionally validity_mode: "period" with effective_date and end_date. It additionally requires credentials:read and the view employees permission.

Response: { "ok": true, "verification": { public_id, type, family, title, status, issued_at, verify_url, … } }.

GET|POST /qr — scope verify:read#

Returns the QR code of a verification. Provide one of verify_url, public_id or a known doc_id; size is optional.

{
  "ok": true,
  "verify_url": "https://check.ivqa.org/verification/document/IVQA-DOC-2026-7ZK3QW2P?sig=…",
  "qr_url": "https://app.ivqa.org/qr/image?d=…&s=300&frame=none"
}

qr_url is an IVQA-hosted PNG that encodes only the public verify_url. Insert that image in the document; do not generate your own QR code.

GET /verification/status — scope credentials:read#

Query public_id. Returns the ownership-checked status and scan counters:

{
  "ok": true,
  "verification": {
    "public_id": "IVQA-DOC-2026-7ZK3QW2P",
    "type": "document",
    "title": "Attestation",
    "status": "valid",
    "issued_at": "2026-08-03 09:10:00",
    "verify_url": "https://check.ivqa.org/verification/document/IVQA-DOC-2026-7ZK3QW2P?sig=…",
    "scans": { "total_scans": 12, "valid_scans": 11, "invalid_scans": 1, "last_scan_at": "2026-08-03 10:22:00" }
  }
}

A public_id that belongs to another organization returns 404 not_found — the API never discloses other tenants' credentials.

POST /metadata — scope verify:write#

Persists or refreshes the editor document's metadata (doc_id, product, title, external_url). Response: { "ok": true, "document_id": 55 }.

Example: check a verification with cURL#

curl -s "https://api.ivqa.org/api/ext/verification/status?public_id=IVQA-DOC-2026-7ZK3QW2P" \
  -H "Authorization: Bearer $IVQA_TOKEN"