# Start a real-person liveness verification session

Start a BytePlus/Volcengine Ark real-person liveness verification for an end user. Returns an H5 link, a BytedToken for polling, the callback URL, and a server-rendered QR code (base64 PNG data URL) that integrators can embed directly in an `<img>` tag for the end user to scan.

Account prerequisites: the calling account must have the trusted_creator tier enabled and enterprise verification approved.

**Third-party SaaS integrators** can pass `callback_url` + `external_user_id` in the body to:
- Skip building a polling loop on `validate-result` — we 302-redirect the end-user back to your `callback_url` on completion (with `group_id`, `status`, `external_user_id` appended).
- Scope the resulting GroupId to a specific end-user inside your tenant so list / get / update / delete is automatically isolated.

## POST /v1/asset-groups/validate-session

> Start a real-person liveness verification session

Start a BytePlus/Volcengine Ark real-person liveness verification for an end user. Returns an H5 link, a BytedToken for polling, the callback URL, and a server-rendered QR code (base64 PNG data URL) that integrators can embed directly in an `<img>` tag for the end user to scan.

Account prerequisites: the calling account must have the trusted_creator tier enabled and enterprise verification approved.

**Third-party SaaS integrators** can pass `callback_url` + `external_user_id` in the body to:
- Skip building a polling loop on `validate-result` — we 302-redirect the end-user back to your `callback_url` on completion (with `group_id`, `status`, `external_user_id` appended).
- Scope the resulting GroupId to a specific end-user inside your tenant so list / get / update / delete is automatically isolated.

### Authentication

`Authorization: Bearer tr-xxx`

### Request Body

Content-Type: `application/json`

- **callback_url** `string`  
  Where the end-user lands after H5 verification. Must be `http(s)` with a host.
- **external_user_id** `string`  
  Optional third-party SaaS end-user identifier (opaque, ≤128 chars). Persisted alongside the resulting GroupId in `user_asset_groups`; same value must be passed on subsequent CRUD calls to see this group.
- **model** `string`  
  Optional. When it resolves to an explicit relay channel (e.g. doubao-seedance-2-0-pro),

### Response

- **ResponseMetadata** `object`  
  Ark request metadata
- **Result** `object`  
  
- **Result.H5Link** `string`  
  H5 link to the liveness verification page, valid for 120 seconds. The end user opens this link in a mobile browser to complete facial recognition.
- **Result.BytedToken** `string`  
  Unique token for this verification session. Used to poll validate-result for the outcome. Valid for 120 seconds.
- **Result.CallbackURL** `string`  
  The URL the H5 page redirects to after liveness verification completes (the XRToken frontend verify-callback page).
- **Result.QRCodeDataURL** `string`  
  Base64-encoded PNG (512×512) of the H5Link, in data-URL form ready to embed in `<img src={QRCodeDataURL}>`. Callers can alternatively render their own QR from the H5Link string.

### Error Codes

- `401`: 
- `403`: Insufficient permissions (tier_insufficient / enterprise_required)
- `502`:
