List IDV Sessions for a User
Retrieve key details of all hosted KYC/KYB sessions attempted for a user. To view the full details of a specific session, including checks and verified data, use [GET View an IDV Session](/api-reference/idv-sessions/view-idv-session).
[Read more about hosted KYC/KYB](/guides/users/verification/hosted) **→**
Authentication
AuthorizationBearer
Bearer authentication of the form `Bearer <token>`, where token is your auth token.
If your platform is using a [proxy](/guides/sca/proxy-management) to take SCA-triggering action on behalf of users, you also need to integrate [mTLS authentication](/guides/sca/platform) and use the `api-mtls` base URL.
Path parameters
ClientId
Platform's API account identifier, associated with the API key.
UserId
The unique identifier of the user.
Response
Success
Id
Max length: 128 characters (see data formats for details)
The unique identifier of the object.
Status
The status of the overall IDV Session:
PENDING– Session created. TheHostedUrlis valid for completion, regardless of whether the user has started or submitted the session.REVIEW– One or more automated checks was neither successful nor refused, so the session was sent for manual review by Mangopay’s teams. This temporary state is only applicable to Legal users and can transition toREFUSEDorVALIDATED.VALIDATED– - The session was validated and the User became KYC/KYB verified (indicated by the User object’sKYCLevel). When theStatuschanges toVALIDATED, the verified data inChecks.Datais used to replace existing data in the User object.REFUSED– The session was refused and the User is not KYC/KYB verified. TheChecks.CheckStatusshows which checks wereREFUSEDand theChecks.Reasonsshows the refused reason types and comment (which is custom text in the case of manual review for Legal users).EXPIRED– The IDV Session expired and can no longer be used. By default, this happens 7 days after theCreationDate. However, if the IDV Session contains the liveness step and that step has been started (the QR code was generated), the session instead expires 1 hour after the liveness step started. The IDV Session contains the liveness step for Natural users, Soletrader users, and Business/Organization users on the legacy integrated flow. In the multi-session PSC flow, the main IDV Session never contains the liveness step (so it always follows the 7-day rule) – the liveness check is performed in each PSC Session instead, which follows the same 7-day/1-hour rule independently.OUT_OF_DATE– The IDV Session is not valid because the user’s KYC/KYB verification status was downgraded by Mangopay.
CreationDate
Unix timestamp (UTC) of the date and time the object was created.
LastUpdate
Unix timestamp (UTC) of the date and time the session was last updated.