Disclosure Requests
Create Disclosure Request
Ask a wallet holder to disclose a verified fact to your instance
POST
Asks the holder of a wallet to disclose one verified fact to your instance. The holder answers on verify.trusset.org with a consent the wallet signs and, for some facts, a zk-STARK proof from their KYC proof bundle.
A wallet can have one open request per scope from your instance. Requests made in the Issuer Portal count toward this.
Creating a request sends the holder nothing. Tell them to sign in at verify.trusset.org with the wallet, in the same environment as your instance. No webhook reports the answer either, so read the request with Get Disclosure Request.
Scopes
What each answer proves, and what it leaves undisclosed, is set out on Get Disclosure Request.
What the holder sees and signs
The holder signs in by signing a message with the wallet. Each open request for that wallet shows your issuer name, or your instance name when there is none, with the scope, yourmessage, your referenceUrl and the expiry.
Approving signs this EIP-712 consent with the wallet. Declining needs no signature.
chainId is 1 for a production instance and 11155111 (Sepolia) for a development one. reference is an empty string when you send no referenceUrl, and expiresAt is in Unix seconds.
How a request resolves
A request startsOPEN and ends in one of four states. APPROVED and DECLINED are the holder’s answers. CANCELLED is yours, through Cancel Disclosure Request. EXPIRED applies once expiresAt passes without an answer, and the holder can no longer respond.
Expiry is applied when requests are read, so a list or a fetch never shows an overdue request as OPEN.
Approval reads the identity register the wallet was verified on. That is the Trusset ID Register first, then the issuer-owned registers of instances that hold the wallet as a customer. A wallet with no identity root there cannot approve, and a register that cannot be read blocks approval until it can.
An approval does not require the identity to be current. A revoked or expired identity keeps its root and can still approve, so read disclosure.chain.isVerified before relying on the answer.
Body Parameters
string
required
The wallet whose holder you ask, as
0x and 40 hex characters. Send it lowercase or correctly checksummed. It is returned checksummed.string
required
AGE, COUNTRY or FULL_KYC, in any case.string
An
https link the holder can open, such as the case the request belongs to. At most 512 characters, with no user name or password in it. It is normalised, so a bare host gains a trailing slash, and it is part of the signed consent.string
Shown to the holder. At most 280 characters after the ends are trimmed. Control characters other than tabs and line breaks are removed first.
integer
default:"14"
Days the holder has to answer, from 1 to 90.
Response Fields
object
