Changes.2026.10.07

What's New


POST /api/identity-store/stores/{storeName}/biometrics/authentications/voice/{sessionId}

Continue a voice authentication session with additional audio data.

POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics/authentications/voice

Initiate voice authentication for a user.

GET /api/identity-store/stores/{storeName}/users/{userId}/authentications/{id}/presentedData

Get the presented data for a user authentication record by internal ID

GET /api/identity-store/stores/{storeName}/users/{extId}/authentications/{id}/presentedData/ext

Get the presented data for a user authentication record by external ID

DELETE /api/identity-store/stores/{storeName}/users/{userId}/biometrics/types/{type}/subtypes/{subtype}/partialEnrolment

Delete a partial enrolment for a user identified by internal user ID with the specified type and subtype

POST /api/identity-store/stores/{storeName}/users/{userExtId}/biometrics/authentications/voice/ext

Initiate voice authentication for a user where the user is identified by their external ID.

GET /api/identity-store/stores/{storeName}/users/{extUserId}/biometrics/types/{type}/subtypes/{subtype}/versions/{versionId}/data/ext

Get a biometric version sensitive data for a user identified by external ID with the specified type, subtype and versionId

POST /api/identity-store/stores/{storeName}/biometrics

Enrol a biometric within an identity store, creating the user to hold the enrolment if one does not exist

DELETE /api/identity-store/stores/{storeName}/users/{userExtId}/biometrics/types/{type}/subtypes/{subtype}/partialEnrolment/ext

Delete a partial enrolment for a user identified by external user ID with the specified type and subtype

What's Changed


POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics
Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 2002: A biometric for this user with a duplicate type and subtype exists

  • 2003: A data integrity violation occurred when saving the biometric to the database

  • 2004: The biometric metadata resource could not be loaded.

  • 2005: The biometric type is not supported

  • 2006: The biometric subtype is not supported by the biometric metadata.

  • 2012: The biometric type is missing.

  • 2014: The subtype biometric data is too long for the specified subtype and can't be stored in the database.

  • 2015: The user is not in a state to allow this operation.

  • 2018: The required validation service was not found in the biometric metadata.

  • 2019: The configured validation service is not of the expected type.

  • 2020: The supplied ASV TI voice template is missing the required speechDuration attribute.

  • 2021: The supplied ASV TI voice template has an invalid speechDuration value.

  • 2022: The request biometric contains call metadata but an unexpected sourceType attribute.

  • 2023: A chunk reference is not in the expected format.

  • 2024: A chunk reference has a tenant ID that does not match the request tenant ID.

  • 2025: A chunk reference has a channel inconsistent with the previous chunk for the same call.

  • 2026: A chunk reference has a call ID that does not match the current call.

  • 2027: A chunk reference has a start time before the call start time.

  • 2028: A chunk reference has a created time before the audio start time.

  • 2029: The chunk references are not in time order.

  • 3024: The request supplies chunk references but the existing partial enrolment has none.

  • 3025: The request supplies call metadata but the existing partial enrolment has none.

  • 3026: The callMetadata attribute is invalid or missing required fields.

  • 3027: The callMetadata attribute is missing the required callId field.

  • 3028: No partial reference biometric was found to update during enrolment.

  • 3029: Failed to consolidate the voice biometric audio data.

  • 3030: No voice biometric data was found in the request.

  • 3031: No voice biometric data was found in the stored version.

  • 3032: The biometric status is invalid for this operation.

  • 3034: The configured TI voice service is newer than the one used to start the partial enrolment and legacy continuation is disabled.

  • 3035: The stored partial enrolment biometric is invalid.

  • 3037: The request call metadata callId does not match the last callId of the existing partial enrolment.

  • 3042: A partial enrolment is already in progress for this user, type and subtype.

  • 3049: Voice authentication is not configured for the store.

  • 3050: The ASV transform service returned a client error.

  • 3051: The ASV transform service returned a server error.

  • 3052: The ASV transform service returned an invalid response.

  • 3053: The voice transform failed with a continuity error.

  • 3058: The biometric request contains an invalid configuration.

  • 3059: The biometric request contains an invalid QC template.

  • 3060: No suitable ROC curve was found for the supplied speech durations.

  • 3061: No ASV TI service configuration was found for the store.

  • 20113: The biometric subtype is missing.

  • 20114: The biometric data is missing.

  • 20120: An error occurred while generating the face template (face transformation service returned an error).

Changed response : 404 Not Found

A required entity was not found. Possible error codes:

  • 90: Tenant not found

  • 100: Store not found

  • 500: User not found

  • 1000: The biometric object could not be stored in or retrieved from the object store (S3).

GET /api/identity-store/stores/{storeName}/users/{userId}/passkeys/{id}
Return Type:

Changed response : 200 OK

User passkey retrieved successfully

  • Changed content type : application/json

    • Changed property publicKey (object)

      The public key associated with the authenticator. Used to verify authenticator assertions.

      • Added property params (object)

POST /api/identity-store/stores/{storeName}/users/{userId}/passkeys/{id}
Return Type:

Changed response : 200 OK

User passkey updated successfully

  • Changed content type : application/json

    • Changed property publicKey (object)

      The public key associated with the authenticator. Used to verify authenticator assertions.

      • Added property params (object)

POST /api/identity-store/stores/{storeName}/users/{userExtId}/biometrics/ext
Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 2002: A biometric for this user with a duplicate type and subtype exists

  • 2003: A data integrity violation occurred when saving the biometric to the database

  • 2004: The biometric metadata resource could not be loaded.

  • 2005: The biometric type is not supported

  • 2006: The biometric subtype is not supported by the biometric metadata.

  • 2012: The biometric type is missing.

  • 2014: The subtype biometric data is too long for the specified subtype and can't be stored in the database.

  • 2015: The user is not in a state to allow this operation.

  • 2018: The required validation service was not found in the biometric metadata.

  • 2019: The configured validation service is not of the expected type.

  • 2020: The supplied ASV TI voice template is missing the required speechDuration attribute.

  • 2021: The supplied ASV TI voice template has an invalid speechDuration value.

  • 2022: The request biometric contains call metadata but an unexpected sourceType attribute.

  • 2023: A chunk reference is not in the expected format.

  • 2024: A chunk reference has a tenant ID that does not match the request tenant ID.

  • 2025: A chunk reference has a channel inconsistent with the previous chunk for the same call.

  • 2026: A chunk reference has a call ID that does not match the current call.

  • 2027: A chunk reference has a start time before the call start time.

  • 2028: A chunk reference has a created time before the audio start time.

  • 2029: The chunk references are not in time order.

  • 3024: The request supplies chunk references but the existing partial enrolment has none.

  • 3025: The request supplies call metadata but the existing partial enrolment has none.

  • 3026: The callMetadata attribute is invalid or missing required fields.

  • 3027: The callMetadata attribute is missing the required callId field.

  • 3028: No partial reference biometric was found to update during enrolment.

  • 3029: Failed to consolidate the voice biometric audio data.

  • 3030: No voice biometric data was found in the request.

  • 3031: No voice biometric data was found in the stored version.

  • 3032: The biometric status is invalid for this operation.

  • 3034: The configured TI voice service is newer than the one used to start the partial enrolment and legacy continuation is disabled.

  • 3035: The stored partial enrolment biometric is invalid.

  • 3037: The request call metadata callId does not match the last callId of the existing partial enrolment.

  • 3042: A partial enrolment is already in progress for this user, type and subtype.

  • 3049: Voice authentication is not configured for the store.

  • 3050: The ASV transform service returned a client error.

  • 3051: The ASV transform service returned a server error.

  • 3052: The ASV transform service returned an invalid response.

  • 3053: The voice transform failed with a continuity error.

  • 3058: The biometric request contains an invalid configuration.

  • 3059: The biometric request contains an invalid QC template.

  • 3060: No suitable ROC curve was found for the supplied speech durations.

  • 3061: No ASV TI service configuration was found for the store.

  • 20113: The biometric subtype is missing.

  • 20114: The biometric data is missing.

  • 20120: An error occurred while generating the face template (face transformation service returned an error).

Changed response : 404 Not Found

A required entity was not found. Possible error codes:

  • 90: Tenant not found

  • 100: Store not found

  • 503: User not found

  • 1000: The biometric object could not be stored in or retrieved from the object store (S3).

POST /api/identity-store/stores/{storeName}/users/{userExtId}/passkeys/{id}/ext
Return Type:

Changed response : 200 OK

User passkey updated successfully

  • Changed content type : application/json

    • Changed property publicKey (object)

      The public key associated with the authenticator. Used to verify authenticator assertions.

      • Added property params (object)

POST /api/identity-store/events/queries/start
Request:

Changed content type : application/json

  • Added property info (object)

    Optional criteria to query the contents of the event info map. Each map key is the name of the info field to match on, and the value specifies the match type and value. The info field name (map key) is matched case insensitively. The match value is compared as stored: an EXACT match requires the whole value to match, a LIKE match is added to the query as LIKE %{matchValue}%.

Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 822: Error trying to start the Athena query

  • 826: Invalid info query criteria - both matchType and matchValue must be supplied


POST /api/identity-store/stores/{storeName}/users/{extId}/biometrics/{type}/ext
Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 2007: All biometrics of the specified type are already in the specified state.

  • 2030: No status was provided in the request.

  • 2031: The requested status is not allowed to be set (for example the internal PARTIAL_ENROLLMENT status).

  • 2032: The biometrics of the specified type are in a status (for example the internal PARTIAL_ENROLLMENT status) that cannot be updated.

GET /api/identity-store/stores/{storeName}/users
Parameters:

Added: searchMode in query

Search mode. Default if not supplied is STANDARD which is a backwards-compatible mode which doesn't return any authentication timing information. Other options are LAST_AUTHENTICATED which includes lastAuthenticatedDtm for each user, and LAST_AUTHENTICATED_EXTENDED which additionally includes lastAuthentication (most recent authenticator) and lastAuthentications (most recent authenticator per factor type).

POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics/{type}
Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 2007: All biometrics of the specified type are already in the specified state.

  • 2030: No status was provided in the request.

  • 2031: The requested status is not allowed to be set (for example the internal PARTIAL_ENROLLMENT status).

  • 2032: The biometrics of the specified type are in a status (for example the internal PARTIAL_ENROLLMENT status) that cannot be updated.

POST /api/identity-store/stores/{storeName}/users/{extId}/biometrics/authentications/face/ext
Return Type:

Changed response : 400 Bad Request

An error occurred - including the face match failing.

NOTE For convenience the updated user object is returned when there is a face match failure because it may contain updated information about the user lock state.

Possible error codes:

  • 8: Face algorithm not supported

  • 2006: The biometric subtype is not supported

  • 2100: The user is locked so authentication cannot be performed

  • 2101: The face modality is locked so authentication cannot be performed

  • 2102: The user is disabled so authentication cannot be performed

  • 2103: The presented biometric is disabled so authentication cannot be performed

  • 20114: Biometric data is not supplied in the request

  • 20115: The specified biometric type is not supported

  • 20120: An unexpected error occurred while generating face template

  • 20121: An error occurred while attempting to perform a face match

  • 20122: There is no suitable face data available for matching against the presented sample

  • 20123: The matching process data is missing from the request

  • 20124: The matching algorithm is missing from the request

  • 20125: The matching threshold must be between 0 and 1

  • 20126: The internal matching threshold must be between 0 and 1

POST /api/identity-store/stores/{storeName}/users/{userId}/biometrics/authentications/face
Return Type:

Changed response : 400 Bad Request

An error occurred - including the face match failing.

NOTE For convenience the updated user object is returned when there is a face match failure because it may contain updated information about the user lock state.

Possible error codes:

  • 8: Face algorithm not supported

  • 2006: The biometric subtype is not supported

  • 2100: The user is locked so authentication cannot be performed

  • 2101: The face modality is locked so authentication cannot be performed

  • 2102: The user is disabled so authentication cannot be performed

  • 2103: The presented biometric is disabled so authentication cannot be performed

  • 20114: Biometric data is not supplied in the request

  • 20115: The biometric type is not supported

  • 20120: An unexpected error occurred while generating face template

  • 20121: An error occurred while attempting to perform a face match

  • 20122: There is no suitable face data available for matching against the presented sample

  • 20123: The matching process data is missing from the request

  • 20124: The matching algorithm is missing from the request

  • 20125: The matching threshold must be between 0 and 1

  • 20126: The internal matching threshold must be between 0 and 1

GET /api/identity-store/stores/{storeName}
Return Type:

Changed response : 200 OK

Store retrieved successfully

  • Changed content type : application/json

    • Changed property configuration (object)

      Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication

      • Added property voiceAuthenticationConfig (object)

        Voice authentication configuration settings

POST /api/identity-store/stores/{storeName}
Request:

The store to update. Omit voiceAuthenticationConfig to leave the persisted voice configuration unchanged; send {} to enable voice with server defaults; or send a populated object to set specific values (omitted object-typed fields are filled with server defaults).

Changed content type : application/json

  • Changed property configuration (object)

    Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication

    • Added property voiceAuthenticationConfig (object)

      Voice authentication configuration settings

Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 102: A store with a duplicate name exists

  • 104: Store name not provided

  • 107: The invalid counts before locking must be provided

  • 108: The invalid counts values must ascend

  • 109: The number of temporary lock durations must be one less than the number of temporary lock counts

  • 110: Each temporary lock duration must be provided

  • 2300: The relying party ID is not secure

  • 3000: No TI voice services configured

  • 3001: Unsupported TI voice service algorithm

  • 3002: Invalid minimum speech for enrolment (must be > 0)

  • 3003: Invalid minimum speech for verification (must be > 0)

  • 3004: Invalid continuity threshold for enrolment (must be 0-1)

  • 3005: Invalid continuity merge threshold for enrolment (must be 0-1)

  • 3006: Invalid continuity merge duration for enrolment (must be >= 0)

  • 3007: Invalid continuity threshold for verification (must be 0-1)

  • 3008: Invalid continuity merge threshold for verification (must be 0-1)

  • 3009: Invalid continuity merge duration for verification (must be >= 0)

  • 3010: Default locale must be specified in ASV verification score thresholds

  • 3011: No locale-specific ASV verification score thresholds specified

  • 3012: Default locale does not have corresponding ASV thresholds

  • 3013: No ASV verification score thresholds specified for locale

  • 3014: Invalid enrolment speech seconds in ASV threshold (must be > 0)

  • 3015: Invalid verification speech seconds in ASV threshold (must be > 0)

  • 3016: Invalid ASV verification score threshold (must be 0-1)

  • 3017: No ASV verification score thresholds specified

  • 3018: Invalid voice TI thresholds configuration

  • 3019: No voice matching algorithm specified

  • 3023: Invalid voice authentication session duration (must be > 0)

  • 3057: Invalid maximum speech for verification (must be >= minimum speech when set > 0)

  • 20125: The face matching threshold must be between 0 and 1

  • 20126: The internal face matching threshold must be between 0 and 1

Changed response : 200 OK

Store updated successfully

  • Changed content type : application/json

    • Changed property configuration (object)

      Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication

      • Added property voiceAuthenticationConfig (object)

        Voice authentication configuration settings

POST /api/identity-store/stores
Request:

Changed content type : application/json

  • Changed property configuration (object)

    Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication

    • Added property voiceAuthenticationConfig (object)

      Voice authentication configuration settings

Return Type:

Changed response : 400 Bad Request

An error occurred. Possible error codes:

  • 101: Max number of stores reached for this tenant

  • 102: A store with a duplicate name exists

  • 104: Store name not provided

  • 107: The invalid counts before locking must be provided

  • 108: The invalid counts values must ascend

  • 109: The number of temporary lock durations must be one less than the number of temporary lock counts

  • 110: Each temporary lock duration must be provided

  • 2300: The relying party ID is not secure

  • 3000: No TI voice services configured

  • 3001: Unsupported TI voice service algorithm

  • 3002: Invalid minimum speech for enrolment (must be > 0)

  • 3003: Invalid minimum speech for verification (must be > 0)

  • 3004: Invalid continuity threshold for enrolment (must be 0-1)

  • 3005: Invalid continuity merge threshold for enrolment (must be 0-1)

  • 3006: Invalid continuity merge duration for enrolment (must be >= 0)

  • 3007: Invalid continuity threshold for verification (must be 0-1)

  • 3008: Invalid continuity merge threshold for verification (must be 0-1)

  • 3009: Invalid continuity merge duration for verification (must be >= 0)

  • 3010: Default locale must be specified in ASV verification score thresholds

  • 3011: No locale-specific ASV verification score thresholds specified

  • 3012: Default locale does not have corresponding ASV thresholds

  • 3013: No ASV verification score thresholds specified for locale

  • 3014: Invalid enrolment speech seconds in ASV threshold (must be > 0)

  • 3015: Invalid verification speech seconds in ASV threshold (must be > 0)

  • 3016: Invalid ASV verification score threshold (must be 0-1)

  • 3017: No ASV verification score thresholds specified

  • 3018: Invalid voice TI thresholds configuration

  • 3019: No voice matching algorithm specified

  • 3023: Invalid voice authentication session duration (must be > 0)

  • 3057: Invalid maximum speech for verification (must be >= minimum speech when set > 0)

  • 20125: The face matching threshold must be between 0 and 1

  • 20126: The internal face matching threshold must be between 0 and 1

Changed response : 201 Created

Store created successfully

  • Changed content type : application/json

    • Changed property configuration (object)

      Identity Store configuration settings. Contains global settings, user locking configuration and policies for face, appkey and passkey registration and authentication

      • Added property voiceAuthenticationConfig (object)

        Voice authentication configuration settings


GET /api/identity-store/stores/{storeName}/users/{userId}/authentications/{id}
Return Type:

Changed response : 200 OK

User authentication record retrieved successfully

  • Changed content type : application/json

    • Changed property authAuditDisplayInfo (object)

      An authentication audit dto, containing structures for app keys, pass keys, biometrics and TOTPs.

      • Added property voiceBiometricAuditInfo (object)

        An authentication audit dto containing extra details required by the UI for a passive voice authentication audit.

      • Changed property biometricAuditInfo (object)

        An authentication audit dto containing extra details required by the UI for a face authentication audit.

    • Changed property authAuditRecord (object)

      An authentication audit record An authentication record contains common fields such as the type and references to the tenant, store and user and specific information depending on the type: appkey/passkey/biometric/TOTP.

      • Added property voiceAuthenticationRecord (object)

        The results of a voice authentication

        • Property authId (object)

          Optional authentication ID from the external authentication sytem

        • Property presentedSubtype (object)

          The voice subtype, for example the voice algorithm Image of the presented sample.

        • Property referenceSubtype (object)

          The voice subtype, for example the voice template DVASVTI5_8K of the reference sample.

        • Property referenceVersionId (object)

          The voice version ID, of the reference sample.

        • Property sourceReferenceSubtype (object)

          The voice subtype, of the source of the reference sample.

        • Property sourceReferenceVersionId (object)

          The voice version ID, of the source of the reference sample.

        • Property status (object)

          The authentication status, for example SUCCESS.

          Enum values:

          • SUCCESS

          • FAILURE

          • INCOMPLETE

          • UNKNOWN

        • Property rawScore (object)

          The internal match score.

        • Property score (object)

          The authentication score matched against the threshold. For a match the score will be equal to or below the threshold.

        • Property threshold (object)

          The authentication threshold.

        • Property policy (object)

          The policy used for the authentication.

        • Property voiceMatcherVersion (object)

          The voice matcher version used for the authentication.

        • Property presentedData (object)

          The authentication data, i.e. the voice sample or template.

        • Property contentType (object)

          The content type of the authentication data.

        • Property chunkReferences (object)

          References to the voice audio chunks used for authentication.

        • Property sourceType (object)

          The source type of the reference sample, for example CALL.

        • Property callMetadataList (object)

          Call metadata supplied with the authentication request.

        • Property config (object)

          Configuration supplied with the authentication request.

        • Property metadata (object)

          Metadata supplied with from a trust web client

          • Property device (object)

            Information extracted from the device where the appkey resides

            • Property appId (object)

              Identifies the device app which owns the appkey

            • Property deviceId (object)

              Identifies the device on which the app resides

              NOTE This identifier is not trustworthy and is not used. The appId is used throughout the system as the proxy device ID because it is always available.

            • Property make (object)

              The device make

            • Property model (object)

              The device model

            • Property osVersion (object)

              The device OS version

            • Property osType (object)

              The device OS type, for example android

            • Property sdkVersion (object)

              The device client SDK version

            • Property name (object)

              The device friendly name

            • Property notificationToken (object)

              A push notification token provided by the device

            • Property healthCheckPassed (object)

              Whether the device health check passed Only available if the HEALTH_CHECK extension is enabled in the appkey registration policy

            • Property environmentCheckResult (object)

              The device environment. Possibly values:

              • Passed: App cannot be debugged and is not running in an emulator.

              • Emulator: App is running in an emulator.

              • Debugger: App can be debugged. Only available if the ENVIRONMENT_CHECK extension is enabled in the appkey registration policy

          • Property locationByIp (object)

            Location metadata

            • Property ipAddress (object)

            • Property country (object)

            • Property city (object)

          • Property userAgent (object)

            User agent metadata

            • Property name (object)

            • Property version (object)

        • Property context (object)

          Context supplied with the authentication request.

      • Changed property type (object)

        The type of audit, for example Face

        Added enum values:

        • VoiceActive

        • VoicePassive Removed enum values:

        • Voice_TD

        • Voice_TI

GET /api/identity-store/stores/{storeName}/users/{extId}/authentications/{id}/ext
Return Type:

Changed response : 200 OK

User authentication record retrieved successfully

  • Changed content type : application/json

    • Changed property authAuditDisplayInfo (object)

      An authentication audit dto, containing structures for app keys, pass keys, biometrics and TOTPs.

      • Added property voiceBiometricAuditInfo (object)

        An authentication audit dto containing extra details required by the UI for a passive voice authentication audit.

      • Changed property biometricAuditInfo (object)

        An authentication audit dto containing extra details required by the UI for a face authentication audit.

    • Changed property authAuditRecord (object)

      An authentication audit record An authentication record contains common fields such as the type and references to the tenant, store and user and specific information depending on the type: appkey/passkey/biometric/TOTP.

      • Added property voiceAuthenticationRecord (object)

        The results of a voice authentication

      • Changed property type (object)

        The type of audit, for example Face

        Added enum values:

        • VoiceActive

        • VoicePassive Removed enum values:

        • Voice_TD

        • Voice_TI

GET /api/userdata-server/processDefinitions/{processDefnId}/processInstances/{processInstanceId}/userdata
Return Type:

Changed response : 200 OK

OK

  • Changed content type : */*

    • Added property calls (object)

      Calls which were captured during the execution of the process instance.