Skip to main content
The browser already holds the card key (unlocked by the passkey, see The card). Signing a one-time message with it proves ownership. The card itself (number, expiry, CVV) is issued after an identity check with Didit, with the holder name taken from the verified document.

Activate the card

One document holds one card: a second card for the same document ends as duplicate. Didit tells the API the result by webhook; the API reads the document from Didit itself, never from the app.
The card number and CVV identify the card in the app only. They are not a payment-network number and nothing accepts them as a credential; payments are passkey-signed authorizations.
Tokens last 30 days. POST /auth/signout ends one early.

Errors

Errors are JSON { error, code }. A missing or expired token returns 401; sign in again.