Activate the card
duplicate. Didit tells the API the
result by webhook; the API reads the document from Didit itself, never from the app.
The card number and CVV identify the card in the app only. They are not a payment-network number and nothing
accepts them as a credential; payments are passkey-signed authorizations.
POST /auth/signout ends one early.
Errors
Errors are JSON{ error, code }. A missing or expired token returns 401; sign in again.