IDCanopy Developers

Authentication

Token exchange for Umbrella API, and the header for Aletheia

Umbrella API: token exchange

POST /auth (base URL: see Environments) with your key in headers, not in the body:

curl -X POST "$UMBRELLA_BASE_URL/auth" \
  -H "Api-Key: $UMBRELLA_API_KEY" \
  -H "Customer-Id: $UMBRELLA_CUSTOMER_ID" \
  -H "Content-Type: application/x-www-form-urlencoded"

Response:

{
  "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...",
  "expires_in": 3600,
  "token_type": "Bearer"
}

expires_in is in seconds (3600 = 1 hour). Use the token as Authorization: Bearer <access_token> on every subsequent Umbrella API call. Re-authenticate before it expires; there is no refresh-token flow.

Aletheia (forensic scoring)

No token exchange. Use your issued key directly:

curl "$ALETHEIA_BASE_URL/..." \
  -H "Authorization: Bearer $ALETHEIA_API_KEY"

IBAN Validation and Address Autocomplete are part of Umbrella API and use the same bearer token. AutoKYB: pending.

On this page