XRToken API Docs

Start a real-person liveness verification session

API Configuration
After saving, the Try It panel below sends real requests with this key.
Base: api.xrtoken.ai

Start a BytePlus/Volcengine Ark real-person liveness verification for an end user. Returns an H5 link, a BytedToken for polling, the callback URL, and a server-rendered QR code (base64 PNG data URL) that integrators can embed directly in an <img> tag for the end user to scan.

Account prerequisites: the calling account must have the trusted_creator tier enabled and enterprise verification approved.

Third-party SaaS integrators can pass callback_url + external_user_id in the body to:

  • Skip building a polling loop on validate-result — we 302-redirect the end-user back to your callback_url on completion (with group_id, status, external_user_id appended).
  • Scope the resulting GroupId to a specific end-user inside your tenant so list / get / update / delete is automatically isolated.
POST
/v1/asset-groups/validate-session

Authorization

BearerAuth
AuthorizationBearer <token>

API key authentication (OpenAI format). Pass in the Authorization header:

Authorization: Bearer tr-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

curl -X post "https://api.xrtoken.ai/v1/asset-groups/validate-session" \  -H "Content-Type: application/json" \  -d '{}'
{
  "ResponseMetadata": {},
  "Result": {
    "H5Link": "https://h5-v2.kych5.com?accessKeyId=AKTP...&bytedToken=...&lng=zh",
    "BytedToken": "string",
    "CallbackURL": "http://example.com",
    "QRCodeDataURL": "data:image/png;base64,iVBORw0KGgoAAAANS..."
  }
}
{
  "error": "invalid or missing API key",
  "type": "auth_error"
}
{
  "error": "string",
  "type": "invalid_request_error"
}
{
  "error": "upstream provider error",
  "type": "server_error"
}