Docs · Get started
Postman collection
Every endpoint, pre-built, with the session id threaded from one request to the next. Import it, paste your own key, and send.
Download
The collection ships with no credential in it. The
apiKey variable is empty; you fill it with a key of your own.
Import and configure
- In Postman, choose Import and select the downloaded
valitel.postman_collection.json. - Mint a key on the dashboard's Keys page with the scopes
verifications:createandverifications:read. Copy it — it is shown once. - Open the collection, go to Variables, and paste the key into
apiKey(the current value column). Save. - Send Create verification. Everything else follows from it.
Variables
| Variable | Ships as | What it is |
|---|---|---|
baseUrl | https://api.valitel.eu | The API origin. Change it if you run Valitel yourself. |
apiKey | empty | Your key. Sent as Authorization: Bearer at the collection level, so every request inherits it. |
verificationId | empty | Set automatically by the Create verification test script, and used by every request that needs an id. |
responseCode | empty | The #response_code=… fragment from a same-device redirect. Paste it before sending Redeem. |
The order to run them in
- Create verification — captures
verificationIdand logswallet_urito the Postman console. - Get verification —
pendinguntil a wallet answers. Present thewallet_urito a wallet, then send it again. - Verification status — the unauthenticated poll, for comparison:
same session,
{id, status}only. - List verifications — your sessions, newest first.
Redeem needs a responseCode from a same-device flow,
and Delete needs a key carrying verifications:delete —
both are in the collection, neither runs as part of the happy path.
Prefer to generate your own?
The API publishes its OpenAPI 3.1 document, generated from the schemas it validates against. Import that instead if you would rather have a client generated for your language:
curl -s https://api.valitel.eu/openapi.json -o valitel-openapi.jsonEvery operation carries a stable operationId (createVerification,
getVerification, listDevices and so on). Generated method names
come from it, and it is never renamed once published.