XRToken API Docs

Poll a real-person liveness verification result

API Configuration
After saving, the Try It panel below sends real requests with this key.
Base: api.xrtoken.ai

Poll the liveness verification result using the BytedToken returned by POST /v1/asset-groups/validate-session. The BytedToken is valid for 120 seconds; poll at 5-second intervals until a terminal state or timeout.

There are three terminal states:

  • Success: the response body contains a GroupId field and status: "active" — the real-person group has been bound to the current user account.
  • Failure: the response body contains ResponseMetadata.Error.
  • Still in progress: the response body has no GroupId — continue polling.
POST
/v1/asset-groups/validate-result

Authorization

BearerAuth
AuthorizationBearer <token>

API key authentication (OpenAI format). Pass in the Authorization header:

Authorization: Bearer tr-xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

In: header

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

application/json

application/json

application/json

application/json

curl -X post "https://api.xrtoken.ai/v1/asset-groups/validate-result" \  -H "Content-Type: application/json" \  -d '{    "bytedToken": "string"  }'
{
  "GroupId": "group-20260418015912-abcde",
  "status": "active",
  "ResponseMetadata": {},
  "Result": {}
}
{
  "error": "model field is required",
  "type": "invalid_request_error"
}
{
  "error": "invalid or missing API key",
  "type": "auth_error"
}
{
  "error": "string",
  "type": "invalid_request_error"
}
{
  "error": "upstream provider error",
  "type": "server_error"
}