Changes.2026.10.07
What's New
POST /api/identity-store/stores/{storeName}/biometrics/authentications/voice/{sessionId}
Continue a voice authentication session with additional audio data.
POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics/authentications/voice
Initiate voice authentication for a user.
GET /api/identity-store/stores/{storeName}/users/{userId}/authentications/{id}/presentedData
Get the presented data for a user authentication record by internal ID
GET /api/identity-store/stores/{storeName}/users/{extId}/authentications/{id}/presentedData/ext
Get the presented data for a user authentication record by external ID
DELETE /api/identity-store/stores/{storeName}/users/{userId}/biometrics/types/{type}/subtypes/{subtype}/partialEnrolment
Delete a partial enrolment for a user identified by internal user ID with the specified type and subtype
POST /api/identity-store/stores/{storeName}/users/{userExtId}/biometrics/authentications/voice/ext
Initiate voice authentication for a user where the user is identified by their external ID.
GET /api/identity-store/stores/{storeName}/users/{extUserId}/biometrics/types/{type}/subtypes/{subtype}/versions/{versionId}/data/ext
Get a biometric version sensitive data for a user identified by external ID with the specified type, subtype and versionId
POST /api/identity-store/stores/{storeName}/biometrics
Enrol a biometric within an identity store, creating the user to hold the enrolment if one does not exist
DELETE /api/identity-store/stores/{storeName}/users/{userExtId}/biometrics/types/{type}/subtypes/{subtype}/partialEnrolment/ext
Delete a partial enrolment for a user identified by external user ID with the specified type and subtype
What's Changed
POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
2002: A biometric for this user with a duplicate type and subtype exists
2003: A data integrity violation occurred when saving the biometric to the database
2004: The biometric metadata resource could not be loaded.
2005: The biometric type is not supported
2006: The biometric subtype is not supported by the biometric metadata.
2012: The biometric type is missing.
2014: The subtype biometric data is too long for the specified subtype and can't be stored in the database.
2015: The user is not in a state to allow this operation.
2018: The required validation service was not found in the biometric metadata.
2019: The configured validation service is not of the expected type.
2020: The supplied ASV TI voice template is missing the required speechDuration attribute.
2021: The supplied ASV TI voice template has an invalid speechDuration value.
2022: The request biometric contains call metadata but an unexpected sourceType attribute.
2023: A chunk reference is not in the expected format.
2024: A chunk reference has a tenant ID that does not match the request tenant ID.
2025: A chunk reference has a channel inconsistent with the previous chunk for the same call.
2026: A chunk reference has a call ID that does not match the current call.
2027: A chunk reference has a start time before the call start time.
2028: A chunk reference has a created time before the audio start time.
2029: The chunk references are not in time order.
3024: The request supplies chunk references but the existing partial enrolment has none.
3025: The request supplies call metadata but the existing partial enrolment has none.
3026: The callMetadata attribute is invalid or missing required fields.
3027: The callMetadata attribute is missing the required callId field.
3028: No partial reference biometric was found to update during enrolment.
3029: Failed to consolidate the voice biometric audio data.
3030: No voice biometric data was found in the request.
3031: No voice biometric data was found in the stored version.
3032: The biometric status is invalid for this operation.
3034: The configured TI voice service is newer than the one used to start the partial enrolment and legacy continuation is disabled.
3035: The stored partial enrolment biometric is invalid.
3037: The request call metadata callId does not match the last callId of the existing partial enrolment.
3042: A partial enrolment is already in progress for this user, type and subtype.
3049: Voice authentication is not configured for the store.
3050: The ASV transform service returned a client error.
3051: The ASV transform service returned a server error.
3052: The ASV transform service returned an invalid response.
3053: The voice transform failed with a continuity error.
3058: The biometric request contains an invalid configuration.
3059: The biometric request contains an invalid QC template.
3060: No suitable ROC curve was found for the supplied speech durations.
3061: No ASV TI service configuration was found for the store.
20113: The biometric subtype is missing.
20114: The biometric data is missing.
20120: An error occurred while generating the face template (face transformation service returned an error).
Changed response : 404 Not Found
A required entity was not found. Possible error codes:
90: Tenant not found
100: Store not found
500: User not found
1000: The biometric object could not be stored in or retrieved from the object store (S3).
GET /api/identity-store/stores/{storeName}/users/{userId}/passkeys/{id}
Return Type:
Changed response : 200 OK
User passkey retrieved successfully
Changed content type :
application/jsonChanged property
publicKey(object)The public key associated with the authenticator. Used to verify authenticator assertions.
Added property
params(object)
POST /api/identity-store/stores/{storeName}/users/{userId}/passkeys/{id}
Return Type:
Changed response : 200 OK
User passkey updated successfully
Changed content type :
application/jsonChanged property
publicKey(object)The public key associated with the authenticator. Used to verify authenticator assertions.
Added property
params(object)
POST /api/identity-store/stores/{storeName}/users/{userExtId}/biometrics/ext
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
2002: A biometric for this user with a duplicate type and subtype exists
2003: A data integrity violation occurred when saving the biometric to the database
2004: The biometric metadata resource could not be loaded.
2005: The biometric type is not supported
2006: The biometric subtype is not supported by the biometric metadata.
2012: The biometric type is missing.
2014: The subtype biometric data is too long for the specified subtype and can't be stored in the database.
2015: The user is not in a state to allow this operation.
2018: The required validation service was not found in the biometric metadata.
2019: The configured validation service is not of the expected type.
2020: The supplied ASV TI voice template is missing the required speechDuration attribute.
2021: The supplied ASV TI voice template has an invalid speechDuration value.
2022: The request biometric contains call metadata but an unexpected sourceType attribute.
2023: A chunk reference is not in the expected format.
2024: A chunk reference has a tenant ID that does not match the request tenant ID.
2025: A chunk reference has a channel inconsistent with the previous chunk for the same call.
2026: A chunk reference has a call ID that does not match the current call.
2027: A chunk reference has a start time before the call start time.
2028: A chunk reference has a created time before the audio start time.
2029: The chunk references are not in time order.
3024: The request supplies chunk references but the existing partial enrolment has none.
3025: The request supplies call metadata but the existing partial enrolment has none.
3026: The callMetadata attribute is invalid or missing required fields.
3027: The callMetadata attribute is missing the required callId field.
3028: No partial reference biometric was found to update during enrolment.
3029: Failed to consolidate the voice biometric audio data.
3030: No voice biometric data was found in the request.
3031: No voice biometric data was found in the stored version.
3032: The biometric status is invalid for this operation.
3034: The configured TI voice service is newer than the one used to start the partial enrolment and legacy continuation is disabled.
3035: The stored partial enrolment biometric is invalid.
3037: The request call metadata callId does not match the last callId of the existing partial enrolment.
3042: A partial enrolment is already in progress for this user, type and subtype.
3049: Voice authentication is not configured for the store.
3050: The ASV transform service returned a client error.
3051: The ASV transform service returned a server error.
3052: The ASV transform service returned an invalid response.
3053: The voice transform failed with a continuity error.
3058: The biometric request contains an invalid configuration.
3059: The biometric request contains an invalid QC template.
3060: No suitable ROC curve was found for the supplied speech durations.
3061: No ASV TI service configuration was found for the store.
20113: The biometric subtype is missing.
20114: The biometric data is missing.
20120: An error occurred while generating the face template (face transformation service returned an error).
Changed response : 404 Not Found
A required entity was not found. Possible error codes:
90: Tenant not found
100: Store not found
503: User not found
1000: The biometric object could not be stored in or retrieved from the object store (S3).
POST /api/identity-store/stores/{storeName}/users/{userExtId}/passkeys/{id}/ext
Return Type:
Changed response : 200 OK
User passkey updated successfully
Changed content type :
application/jsonChanged property
publicKey(object)The public key associated with the authenticator. Used to verify authenticator assertions.
Added property
params(object)
POST /api/identity-store/events/queries/start
Request:
Changed content type : application/json
Added property
info(object)Optional criteria to query the contents of the event
infomap. Each map key is the name of the info field to match on, and the value specifies the match type and value. The info field name (map key) is matched case insensitively. The match value is compared as stored: anEXACTmatch requires the whole value to match, aLIKEmatch is added to the query asLIKE %{matchValue}%.
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
822: Error trying to start the Athena query
826: Invalid info query criteria - both matchType and matchValue must be supplied
POST /api/identity-store/stores/{storeName}/users/{extId}/biometrics/{type}/ext
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
2007: All biometrics of the specified type are already in the specified state.
2030: No status was provided in the request.
2031: The requested status is not allowed to be set (for example the internal PARTIAL_ENROLLMENT status).
2032: The biometrics of the specified type are in a status (for example the internal PARTIAL_ENROLLMENT status) that cannot be updated.
GET /api/identity-store/stores/{storeName}/users
Parameters:
Added: searchMode in query
Search mode. Default if not supplied is
STANDARDwhich is a backwards-compatible mode which doesn't return any authentication timing information. Other options areLAST_AUTHENTICATEDwhich includeslastAuthenticatedDtmfor each user, andLAST_AUTHENTICATED_EXTENDEDwhich additionally includeslastAuthentication(most recent authenticator) andlastAuthentications(most recent authenticator per factor type).
POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics/{type}
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
2007: All biometrics of the specified type are already in the specified state.
2030: No status was provided in the request.
2031: The requested status is not allowed to be set (for example the internal PARTIAL_ENROLLMENT status).
2032: The biometrics of the specified type are in a status (for example the internal PARTIAL_ENROLLMENT status) that cannot be updated.
POST /api/identity-store/stores/{storeName}/users/{extId}/biometrics/authentications/face/ext
Return Type:
Changed response : 400 Bad Request
An error occurred - including the face match failing.
NOTE For convenience the updated user object is returned when there is a face match failure because it may contain updated information about the user lock state.
Possible error codes:
8: Face algorithm not supported
2006: The biometric subtype is not supported
2100: The user is locked so authentication cannot be performed
2101: The face modality is locked so authentication cannot be performed
2102: The user is disabled so authentication cannot be performed
2103: The presented biometric is disabled so authentication cannot be performed
20114: Biometric data is not supplied in the request
20115: The specified biometric type is not supported
20120: An unexpected error occurred while generating face template
20121: An error occurred while attempting to perform a face match
20122: There is no suitable face data available for matching against the presented sample
20123: The matching process data is missing from the request
20124: The matching algorithm is missing from the request
20125: The matching threshold must be between 0 and 1
20126: The internal matching threshold must be between 0 and 1
POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics/authentications/face
Return Type:
Changed response : 400 Bad Request
An error occurred - including the face match failing.
NOTE For convenience the updated user object is returned when there is a face match failure because it may contain updated information about the user lock state.
Possible error codes:
8: Face algorithm not supported
2006: The biometric subtype is not supported
2100: The user is locked so authentication cannot be performed
2101: The face modality is locked so authentication cannot be performed
2102: The user is disabled so authentication cannot be performed
2103: The presented biometric is disabled so authentication cannot be performed
20114: Biometric data is not supplied in the request
20115: The biometric type is not supported
20120: An unexpected error occurred while generating face template
20121: An error occurred while attempting to perform a face match
20122: There is no suitable face data available for matching against the presented sample
20123: The matching process data is missing from the request
20124: The matching algorithm is missing from the request
20125: The matching threshold must be between 0 and 1
20126: The internal matching threshold must be between 0 and 1
GET /api/identity-store/stores/{storeName}
Return Type:
Changed response : 200 OK
Store retrieved successfully
Changed content type :
application/jsonChanged property
configuration(object)Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication
Added property
voiceAuthenticationConfig(object)Voice authentication configuration settings
POST /api/identity-store/stores/{storeName}
Request:
The store to update. Omit
voiceAuthenticationConfigto leave the persisted voice configuration unchanged; send{}to enable voice with server defaults; or send a populated object to set specific values (omitted object-typed fields are filled with server defaults).
Changed content type : application/json
Changed property
configuration(object)Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication
Added property
voiceAuthenticationConfig(object)Voice authentication configuration settings
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
102: A store with a duplicate name exists
104: Store name not provided
107: The invalid counts before locking must be provided
108: The invalid counts values must ascend
109: The number of temporary lock durations must be one less than the number of temporary lock counts
110: Each temporary lock duration must be provided
2300: The relying party ID is not secure
3000: No TI voice services configured
3001: Unsupported TI voice service algorithm
3002: Invalid minimum speech for enrolment (must be > 0)
3003: Invalid minimum speech for verification (must be > 0)
3004: Invalid continuity threshold for enrolment (must be 0-1)
3005: Invalid continuity merge threshold for enrolment (must be 0-1)
3006: Invalid continuity merge duration for enrolment (must be >= 0)
3007: Invalid continuity threshold for verification (must be 0-1)
3008: Invalid continuity merge threshold for verification (must be 0-1)
3009: Invalid continuity merge duration for verification (must be >= 0)
3010: Default locale must be specified in ASV verification score thresholds
3011: No locale-specific ASV verification score thresholds specified
3012: Default locale does not have corresponding ASV thresholds
3013: No ASV verification score thresholds specified for locale
3014: Invalid enrolment speech seconds in ASV threshold (must be > 0)
3015: Invalid verification speech seconds in ASV threshold (must be > 0)
3016: Invalid ASV verification score threshold (must be 0-1)
3017: No ASV verification score thresholds specified
3018: Invalid voice TI thresholds configuration
3019: No voice matching algorithm specified
3023: Invalid voice authentication session duration (must be > 0)
3057: Invalid maximum speech for verification (must be >= minimum speech when set > 0)
20125: The face matching threshold must be between 0 and 1
20126: The internal face matching threshold must be between 0 and 1
Changed response : 200 OK
Store updated successfully
Changed content type :
application/jsonChanged property
configuration(object)Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication
Added property
voiceAuthenticationConfig(object)Voice authentication configuration settings
POST /api/identity-store/stores
Request:
Changed content type : application/json
Changed property
configuration(object)Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication
Added property
voiceAuthenticationConfig(object)Voice authentication configuration settings
Return Type:
Changed response : 400 Bad Request
An error occurred. Possible error codes:
101: Max number of stores reached for this tenant
102: A store with a duplicate name exists
104: Store name not provided
107: The invalid counts before locking must be provided
108: The invalid counts values must ascend
109: The number of temporary lock durations must be one less than the number of temporary lock counts
110: Each temporary lock duration must be provided
2300: The relying party ID is not secure
3000: No TI voice services configured
3001: Unsupported TI voice service algorithm
3002: Invalid minimum speech for enrolment (must be > 0)
3003: Invalid minimum speech for verification (must be > 0)
3004: Invalid continuity threshold for enrolment (must be 0-1)
3005: Invalid continuity merge threshold for enrolment (must be 0-1)
3006: Invalid continuity merge duration for enrolment (must be >= 0)
3007: Invalid continuity threshold for verification (must be 0-1)
3008: Invalid continuity merge threshold for verification (must be 0-1)
3009: Invalid continuity merge duration for verification (must be >= 0)
3010: Default locale must be specified in ASV verification score thresholds
3011: No locale-specific ASV verification score thresholds specified
3012: Default locale does not have corresponding ASV thresholds
3013: No ASV verification score thresholds specified for locale
3014: Invalid enrolment speech seconds in ASV threshold (must be > 0)
3015: Invalid verification speech seconds in ASV threshold (must be > 0)
3016: Invalid ASV verification score threshold (must be 0-1)
3017: No ASV verification score thresholds specified
3018: Invalid voice TI thresholds configuration
3019: No voice matching algorithm specified
3023: Invalid voice authentication session duration (must be > 0)
3057: Invalid maximum speech for verification (must be >= minimum speech when set > 0)
20125: The face matching threshold must be between 0 and 1
20126: The internal face matching threshold must be between 0 and 1
Changed response : 201 Created
Store created successfully
Changed content type :
application/json
GET /api/identity-store/stores/{storeName}/users/{userId}/authentications/{id}
Return Type:
Changed response : 200 OK
User authentication record retrieved successfully
Changed content type :
application/jsonChanged property
authAuditDisplayInfo(object)An authentication audit dto, containing structures for app keys, pass keys, biometrics and TOTPs.
Added property
voiceBiometricAuditInfo(object)An authentication audit dto containing extra details required by the UI for a passive voice authentication audit.
Changed property
biometricAuditInfo(object)An authentication audit dto containing extra details required by the UI for a face authentication audit.
Changed property
authAuditRecord(object)An authentication audit record An authentication record contains common fields such as the type and references to the tenant, store and user and specific information depending on the type: appkey/passkey/biometric/TOTP.
Added property
voiceAuthenticationRecord(object)The results of a voice authentication
Property
authId(object)Optional authentication ID from the external authentication sytem
Property
presentedSubtype(object)The voice subtype, for example the voice algorithm
Imageof the presented sample.Property
referenceSubtype(object)The voice subtype, for example the voice template
DVASVTI5_8Kof the reference sample.Property
referenceVersionId(object)The voice version ID, of the reference sample.
Property
sourceReferenceSubtype(object)The voice subtype, of the source of the reference sample.
Property
sourceReferenceVersionId(object)The voice version ID, of the source of the reference sample.
Property
status(object)The authentication status, for example
SUCCESS.Enum values:
SUCCESSFAILUREINCOMPLETEUNKNOWN
Property
rawScore(object)The internal match score.
Property
score(object)The authentication score matched against the threshold. For a match the score will be equal to or below the threshold.
Property
threshold(object)The authentication threshold.
Property
policy(object)The policy used for the authentication.
Property
voiceMatcherVersion(object)The voice matcher version used for the authentication.
Property
presentedData(object)The authentication data, i.e. the voice sample or template.
Property
contentType(object)The content type of the authentication data.
Property
chunkReferences(object)References to the voice audio chunks used for authentication.
Property
sourceType(object)The source type of the reference sample, for example
CALL.Property
callMetadataList(object)Call metadata supplied with the authentication request.
Property
config(object)Configuration supplied with the authentication request.
Property
metadata(object)Metadata supplied with from a trust web client
Property
device(object)Information extracted from the device where the appkey resides
Property
appId(object)Identifies the device app which owns the appkey
Property
deviceId(object)Identifies the device on which the app resides
NOTE This identifier is not trustworthy and is not used. The
appIdis used throughout the system as the proxy device ID because it is always available.Property
make(object)The device make
Property
model(object)The device model
Property
osVersion(object)The device OS version
Property
osType(object)The device OS type, for example
androidProperty
sdkVersion(object)The device client SDK version
Property
name(object)The device friendly name
Property
notificationToken(object)A push notification token provided by the device
Property
healthCheckPassed(object)Whether the device health check passed Only available if the
HEALTH_CHECKextension is enabled in the appkey registration policyProperty
environmentCheckResult(object)The device environment. Possibly values:
Passed: App cannot be debugged and is not running in an emulator.
Emulator: App is running in an emulator.
Debugger: App can be debugged. Only available if the
ENVIRONMENT_CHECKextension is enabled in the appkey registration policy
Property
locationByIp(object)Location metadata
Property
ipAddress(object)Property
country(object)Property
city(object)
Property
userAgent(object)User agent metadata
Property
name(object)Property
version(object)
Property
context(object)Context supplied with the authentication request.
Changed property
type(object)The type of audit, for example
FaceAdded enum values:
VoiceActiveVoicePassiveRemoved enum values:Voice_TDVoice_TI
GET /api/identity-store/stores/{storeName}/users/{extId}/authentications/{id}/ext
Return Type:
Changed response : 200 OK
User authentication record retrieved successfully
Changed content type :
application/jsonChanged property
authAuditDisplayInfo(object)An authentication audit dto, containing structures for app keys, pass keys, biometrics and TOTPs.
Added property
voiceBiometricAuditInfo(object)An authentication audit dto containing extra details required by the UI for a passive voice authentication audit.
Changed property
biometricAuditInfo(object)An authentication audit dto containing extra details required by the UI for a face authentication audit.
Changed property
authAuditRecord(object)An authentication audit record An authentication record contains common fields such as the type and references to the tenant, store and user and specific information depending on the type: appkey/passkey/biometric/TOTP.
Added property
voiceAuthenticationRecord(object)The results of a voice authentication
Changed property
type(object)The type of audit, for example
FaceAdded enum values:
VoiceActiveVoicePassiveRemoved enum values:Voice_TDVoice_TI
GET /api/userdata-server/processDefinitions/{processDefnId}/processInstances/{processInstanceId}/userdata
Return Type:
Changed response : 200 OK
OK
Changed content type :
*/*Added property
calls(object)Calls which were captured during the execution of the process instance.