Novu Design Workflow
novuhq/novu
Design notification workflows the Novu way — choose channels, set severity, decide when a workflow is critical, configure digests, and route based on subscriber state.
Full Didit identity verification platform management — account creation, API keys, sessions, workflows, questionnaires, users, billing, blocklist, and webhooks.
$ npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills didit-verification-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/didit-verification-management .claude/skills/didit-verification-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "didit-verification-management" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-management into .claude/skills/didit-verification-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "didit-verification-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills didit-verification-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/didit-verification-management .agents/skills/didit-verification-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "didit-verification-management" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-management into .agents/skills/didit-verification-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "didit-verification-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills didit-verification-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/didit-verification-management .cursor/skills/didit-verification-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "didit-verification-management" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-management into .cursor/skills/didit-verification-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "didit-verification-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/didit-verification-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills didit-verification-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/didit-verification-management .gemini/skills/didit-verification-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "didit-verification-management" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-management into .gemini/skills/didit-verification-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "didit-verification-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills didit-verification-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/didit-verification-management .github/skills/didit-verification-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "didit-verification-management" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-management into .github/skills/didit-verification-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "didit-verification-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills didit-verification-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/didit-verification-management .opencode/skills/didit-verification-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "didit-verification-management" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/didit-verification-management into .opencode/skills/didit-verification-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "didit-verification-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
didit-verification-managementFull Didit identity verification platform management — account creation, API keys, sessions, workflows, questionnaires, users, billing, blocklist, and webhooks.
Didit Verification Management is an agent skill from LeoYeAI/openclaw-master-skills. Full Didit identity verification platform management — account creation, API keys, sessions, workflows, questionnaires, users, billing, blocklist, and webhooks. Use when someone needs to create a Didit account, get API keys, set up verification workflows, create or retrieve verification sessions, approve or decline sessions, manage users, check credit balance, top up credits, configure blocklists, configure webhooks programmatically, handle webhook signatures, or perform any platform administration. 45+ endpoints…
Its SKILL.md is about 7.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts (for example `_meta.json`, `scripts/create_session.py` and `scripts/manage_workflows.py`).
It sits in Backend & APIs, covering Webhooks. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonpipFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
verification.didit.meapx.didit.meverify.didit.mecheckout.stripe.comAlso links to:
docs.didit.mebusiness.didit.meFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYDIDIT_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Didit Verification Management loads about 7.3k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 1,828 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,828 words, ~7,341 tokens.
.claude/skills/didit-verification-management/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.The single skill for the entire Didit verification platform. Covers account creation, session management, workflow configuration, questionnaires, user management, billing, blocklist, and webhook configuration — 45+ endpoints across 9 categories.
For standalone verification APIs (ID scan, liveness, face match, AML, etc.), see the individual didit-* skills.
API Reference Links:
Go from nothing to a live verification link in 4 API calls, no browser needed:
import requests
# 1. Register (any email, no business email required)
requests.post("https://apx.didit.me/auth/v2/programmatic/register/",
json={"email": "you@gmail.com", "password": "MyStr0ng!Pass"})
# 2. Check email for 6-char OTP, then verify → get api_key
resp = requests.post("https://apx.didit.me/auth/v2/programmatic/verify-email/",
json={"email": "you@gmail.com", "code": "A3K9F2"})
api_key = resp.json()["application"]["api_key"]
headers = {"x-api-key": api_key, "Content-Type": "application/json"}
# 3. Create a KYC workflow
wf = requests.post("https://verification.didit.me/v3/workflows/",
headers=headers,
json={"workflow_label": "My KYC", "workflow_type": "kyc",
"is_liveness_enabled": True, "is_face_match_enabled": True}).json()
# 4. Create a session → send user to the URL
session = requests.post("https://verification.didit.me/v3/session/",
headers=headers,
json={"workflow_id": wf["uuid"], "vendor_data": "user-123"}).json()
print(f"Send user to: {session['url']}")To add credits: GET /v3/billing/balance/ to check, POST /v3/billing/top-up/ with {"amount_in_dollars": 50} for a Stripe checkout link.
Two auth schemes are used across the platform:
| Endpoints | Auth | Header |
|---|---|---|
| Register, Verify Email, Login | None | (unauthenticated) |
| List Organizations, Get Credentials | Bearer | Authorization: Bearer <access_token> |
| Everything else (sessions, workflows, etc.) | API Key | x-api-key: <api_key> |
Get your api_key via programmatic registration (above) or from Didit Business Console → API & Webhooks.
Base URL: https://apx.didit.me/auth/v2
POST /programmatic/register/| Body | Type | Required | Description |
|---|---|---|---|
email | string | Yes | Any email address |
password | string | Yes | Min 8 chars, 1 upper, 1 lower, 1 digit, 1 special |
Response (201): {"message": "Registration successful...", "email": "..."}
Rate limit: 5 per IP per hour.
POST /programmatic/verify-email/| Body | Type | Required | Description |
|---|---|---|---|
email | string | Yes | Same email from register |
code | string | Yes | 6-character alphanumeric OTP from email |
Response (200):
{
"access_token": "eyJ...",
"refresh_token": "eyJ...",
"expires_in": 86400,
"organization": {"uuid": "...", "name": "..."},
"application": {"uuid": "...", "client_id": "...", "api_key": "YOUR_KEY_HERE"}
}application.api_key is the x-api-key for all subsequent calls.
POST /programmatic/login/| Body | Type | Required | Description |
|---|---|---|---|
email | string | Yes | Account email |
password | string | Yes | Account password |
Response (200): {"access_token": "...", "refresh_token": "...", "expires_in": 86400}
Progressive lockout: 5 fails = 15min, 10 = 1hr, 20 = 24hr.
GET /organizations/me/Auth: Authorization: Bearer <access_token>
Response (200): Array of {"uuid": "...", "name": "...", "contact_email": "..."}
GET /organizations/me/{org_id}/applications/{app_id}/Auth: Authorization: Bearer <access_token>
Response (200): {"uuid": "...", "client_id": "...", "api_key": "..."}
Base URL: https://verification.didit.me/v3
Workflows define verification steps, thresholds, and accepted documents. Each has a UUID used as workflow_id when creating sessions.
Workflow Types:
| Type | Purpose | Typical Features |
|---|---|---|
kyc | Full identity verification (ID + selfie) | ID Verification, Liveness, Face Match, AML, NFC |
adaptive_age_verification | Age gating with ID fallback for borderline cases | Age Estimation, Liveness, per-country age restrictions |
biometric_authentication | Re-verify returning users (no document) | Liveness, Face Match against stored portrait |
address_verification | Verify proof of address documents | Proof of Address, geocoding, name matching |
questionnaire_verification | Custom form/questionnaire verification | Questionnaire, optional ID/liveness add-ons |
email_verification | Email OTP verification as a workflow | Email send/check, breach/disposable detection |
phone_verification | Phone OTP verification as a workflow | Phone send/check, carrier/VoIP detection |
Features (toggleable per workflow): ID Verification, Liveness, Face Match, NFC, AML, Phone, Email, Proof of Address, Database Validation, IP Analysis, Age Estimation, Questionnaire.
GET /v3/workflows/Response (200): Array of workflow objects with uuid, workflow_label, workflow_type, is_default, features, total_price.
POST /v3/workflows/| Body | Type | Default | Description |
|---|---|---|---|
workflow_label | string | auto | Display name |
workflow_type | string | kyc | Workflow template type |
is_default | boolean | false | Set as default |
is_liveness_enabled | boolean | false | Liveness detection |
face_liveness_method | string | passive | "passive", "active_3d", "flashing" |
face_liveness_score_decline_threshold | integer | 50 | Below this → auto-decline |
is_face_match_enabled | boolean | false | Selfie-to-document match |
face_match_score_decline_threshold | integer | 50 | Below this → auto-decline |
face_match_score_review_threshold | integer | 70 | Below this → manual review |
is_aml_enabled | boolean | false | AML/PEP/sanctions screening |
aml_decline_threshold | integer | 80 | Above this → auto-decline |
is_phone_verification_enabled | boolean | false | Phone verification step |
is_email_verification_enabled | boolean | false | Email verification step |
is_database_validation_enabled | boolean | false | Gov database validation |
is_ip_analysis_enabled | boolean | false | IP risk analysis |
is_nfc_enabled | boolean | false | NFC chip reading (mobile only, ePassports) |
is_age_restrictions_enabled | boolean | false | Enable per-country age restrictions (for adaptive_age_verification) |
documents_allowed | object | {} | Restrict accepted countries/doc types (empty = accept all) |
duplicated_user_action | string | no_action | no_action, review, decline (set after creation via update) |
max_retry_attempts | integer | 3 | Max retries per session |
retry_window_days | integer | 7 | Days within which retries are allowed |
Response (201): Workflow object with uuid.
wf = requests.post("https://verification.didit.me/v3/workflows/",
headers={"x-api-key": API_KEY, "Content-Type": "application/json"},
json={"workflow_label": "KYC + AML", "workflow_type": "kyc",
"is_liveness_enabled": True, "is_face_match_enabled": True,
"is_aml_enabled": True}).json()GET /v3/workflows/{settings_uuid}/PATCH /v3/workflows/{settings_uuid}/Partial update — only send fields to change.
DELETE /v3/workflows/{settings_uuid}/Response: 204 No Content. Existing sessions are not affected.
Base URL: https://verification.didit.me/v3
Sessions are the core unit of verification. Every verification starts by creating a session linked to a workflow.
Lifecycle: Create → User verifies at URL → Webhook/poll decision → Optionally update status
Statuses: Not Started, In Progress, In Review, Approved, Declined, Abandoned, Expired, Resubmitted
Rate limits: 300 req/min per method. Session creation: 600/min. Decision polling: 100/min.
POST /v3/session/| Body | Type | Required | Description |
|---|---|---|---|
workflow_id | uuid | Yes | Workflow UUID |
vendor_data | string | No | Your user identifier |
callback | url | No | Redirect URL (Didit appends verificationSessionId + status) |
callback_method | string | No | "initiator", "completer", or "both" |
metadata | JSON string | No | Custom data stored with session |
language | string | No | ISO 639-1 UI language |
contact_details.email | string | No | Pre-fill email for email verification step |
contact_details.phone | string | No | Pre-fill phone (E.164) for phone verification step |
contact_details.send_notification_emails | boolean | No | Send status update emails to user |
contact_details.email_lang | string | No | Language for email notifications (ISO 639-1) |
expected_details.first_name | string | No | Triggers mismatch warning if different (fuzzy match) |
expected_details.last_name | string | No | Expected last name (fuzzy match) |
expected_details.date_of_birth | string | No | YYYY-MM-DD |
expected_details.gender | string | No | "M", "F", or null |
expected_details.nationality | string | No | ISO 3166-1 alpha-3 country code |
expected_details.id_country | string | No | ISO alpha-3 for expected ID document country (overrides nationality) |
expected_details.poa_country | string | No | ISO alpha-3 for expected PoA document country |
expected_details.address | string | No | Expected address (human-readable, for PoA matching) |
expected_details.identification_number | string | No | Expected document/personal/tax number |
expected_details.ip_address | string | No | Expected IP address (logs warning if different) |
portrait_image | base64 | No | Reference portrait for Biometric Auth (max 1MB) |
Response (201):
{
"session_id": "...",
"session_number": 1234,
"session_token": "abcdef123456",
"url": "https://verify.didit.me/session/abcdef123456",
"status": "Not Started",
"workflow_id": "..."
}Send the user to url to complete verification.
GET /v3/session/{sessionId}/decision/Returns all verification results. Image URLs expire after 60 minutes.
Response (200): Full decision with status, features, id_verifications, liveness_checks, face_matches, aml_screenings, phone_verifications, email_verifications, poa_verifications, database_validations, ip_analyses, reviews.
GET /v3/sessions/| Query | Type | Default | Description |
|---|---|---|---|
vendor_data | string | — | Filter by your user identifier |
status | string | — | Filter by status (e.g. Approved, Declined, In Review) |
country | string | — | Filter by ISO 3166-1 alpha-3 country code |
workflow_id | string | — | Filter by workflow UUID |
offset | integer | 0 | Number of items to skip |
limit | integer | 20 | Max items to return |
Response (200): Paginated list with count, next, previous, results[].
DELETE /v3/session/{sessionId}/delete/Response: 204 No Content. Permanently deletes all associated data.
POST /v3/sessions/delete/| Body | Type | Description |
|---|---|---|
session_numbers | array | List of session numbers to delete |
delete_all | boolean | Delete all sessions (use with caution) |
PATCH /v3/session/{sessionId}/update-status/| Body | Type | Required | Description |
|---|---|---|---|
new_status | string | Yes | "Approved", "Declined", or "Resubmitted" |
comment | string | No | Reason for change |
send_email | boolean | No | Send notification email |
email_address | string | Conditional | Required when send_email is true |
email_language | string | No | Email language (default: "en") |
nodes_to_resubmit | array | No | For Resubmitted: [{"node_id": "feature_ocr", "feature": "OCR"}] |
Resubmit requires session to be Declined, In Review, or Abandoned.
GET /v3/session/{sessionId}/generate-pdfRate limit: 100 req/min.
POST /v3/session/{sessionId}/share/Generates a share_token for B2B KYC sharing. Only works for finished sessions.
POST /v3/session/import-shared/| Body | Type | Required | Description |
|---|---|---|---|
share_token | string | Yes | Token from sharing partner |
trust_review | boolean | Yes | true: keep original status; false: set to "In Review" |
workflow_id | string | Yes | Your workflow ID |
vendor_data | string | No | Your user identifier |
A session can only be imported once per partner application.
GET /v3/sessions/{session_id}/reviews/Response (200): Array of review activity items:
[
{
"id": 1,
"action": "status_change",
"old_status": "In Review",
"new_status": "Approved",
"note": "Document verified manually",
"created_at": "2025-06-01T15:00:00Z"
}
]POST /v3/sessions/{session_id}/reviews/| Body | Type | Required | Description |
|---|---|---|---|
new_status | string | Yes | "Approved", "Declined", or "In Review" |
comment | string | No | Review note |
Response (201): The created review item.
Block entities from a session to auto-decline future matches.
POST /v3/blocklist/add/| Body | Type | Required | Description |
|---|---|---|---|
session_id | uuid | Yes | Session to blocklist items from |
blocklist_face | boolean | No | Block biometric face template |
blocklist_document | boolean | No | Block document fingerprint |
blocklist_phone | boolean | No | Block phone number |
blocklist_email | boolean | No | Block email address |
Warning tags on match: FACE_IN_BLOCKLIST, ID_DOCUMENT_IN_BLOCKLIST, PHONE_NUMBER_IN_BLOCKLIST, EMAIL_IN_BLOCKLIST
POST /v3/blocklist/remove/Same structure with unblock_face, unblock_document, unblock_phone, unblock_email.
GET /v3/blocklist/| Query | Type | Description |
|---|---|---|
item_type | string | "face", "document", "phone", "email". Omit for all. |
Custom forms attached to verification workflows. Support 7 element types: short_text, long_text, multiple_choice, checkbox, file_upload, date, number.
GET /v3/questionnaires/POST /v3/questionnaires/| Body | Type | Required | Description |
|---|---|---|---|
title | string | Yes | Display title |
description | string | No | Description shown to users |
default_language | string | No | Default language code |
languages | array | No | Supported languages |
form_elements | array | Yes | Question objects |
Form element:
| Field | Type | Required | Description |
|---|---|---|---|
element_type | string | Yes | One of the 7 types above |
label | object | Yes | Translations: {"en": "Question?", "es": "¿Pregunta?"} |
is_required | boolean | No | Mandatory answer |
options | array | Conditional | Required for multiple_choice/checkbox |
requests.post("https://verification.didit.me/v3/questionnaires/",
headers=headers,
json={
"title": "Employment Details",
"default_language": "en",
"form_elements": [
{"element_type": "short_text",
"label": {"en": "Occupation?"}, "is_required": True},
{"element_type": "multiple_choice",
"label": {"en": "Employment status"},
"options": [{"label": {"en": "Employed"}}, {"label": {"en": "Student"}}]},
]
})GET /v3/questionnaires/{questionnaire_uuid}/PATCH /v3/questionnaires/{questionnaire_uuid}/DELETE /v3/questionnaires/{questionnaire_uuid}/Response: 204 No Content.
Manage verified individuals identified by vendor_data.
GET /v3/users/| Query | Type | Description |
|---|---|---|
status | string | Approved, Declined, In Review, Pending |
search | string | Search by name or identifier |
country | string | ISO 3166-1 alpha-3 |
limit | integer | Results per page (max 200) |
offset | integer | Pagination offset |
Response (200): Paginated list with vendor_data, full_name, status, session_count, issuing_states, approved_emails, approved_phones.
GET /v3/users/{vendor_data}/PATCH /v3/users/{vendor_data}/| Body | Type | Description |
|---|---|---|
display_name | string | Custom display name |
status | string | Manual override: Approved, Declined, In Review |
metadata | object | Custom JSON metadata |
POST /v3/users/delete/| Body | Type | Description |
|---|---|---|
vendor_data_list | array | List of vendor_data strings |
delete_all | boolean | Delete all users |
GET /v3/billing/balance/Response (200):
{
"balance": "142.5000",
"auto_refill_enabled": true,
"auto_refill_amount": "100.0000",
"auto_refill_threshold": "10.0000"
}POST /v3/billing/top-up/| Body | Type | Required | Description |
|---|---|---|---|
amount_in_dollars | number | Yes | Minimum $50 |
success_url | string | No | Redirect after payment |
cancel_url | string | No | Redirect on cancel |
Response (200):
{
"checkout_session_id": "cs_live_...",
"checkout_session_url": "https://checkout.stripe.com/..."
}Present checkout_session_url to the user for payment.
Set up webhooks programmatically — no console needed.
GET /v3/webhook/Response (200):
{
"webhook_url": "https://myapp.com/webhooks/didit",
"webhook_version": "v3",
"secret_shared_key": "whsec_a1b2c3d4e5f6g7h8i9j0...",
"capture_method": "both",
"data_retention_months": null
}| Field | Type | Description |
|---|---|---|
webhook_url | string/null | URL where notifications are sent (null if not configured) |
webhook_version | string | "v1", "v2", or "v3" (v3 recommended) |
secret_shared_key | string | HMAC secret for verifying webhook signatures |
capture_method | string | "mobile", "desktop", or "both" |
data_retention_months | integer/null | Months to retain session data (null = unlimited) |
PATCH /v3/webhook/| Body | Type | Required | Description |
|---|---|---|---|
webhook_url | string/null | No | URL for notifications (set null to disable) |
webhook_version | string | No | "v1", "v2", or "v3" |
rotate_secret_key | boolean | No | true to generate a new secret (old one immediately invalidated) |
capture_method | string | No | "mobile", "desktop", or "both" |
data_retention_months | integer/null | No | 1–120 months, or null for unlimited |
Example — set webhook URL:
requests.patch(
"https://verification.didit.me/v3/webhook/",
headers={"x-api-key": API_KEY, "Content-Type": "application/json"},
json={"webhook_url": "https://myapp.com/webhooks/didit", "webhook_version": "v3"},
)Example — rotate secret:
r = requests.patch(
"https://verification.didit.me/v3/webhook/",
headers={"x-api-key": API_KEY, "Content-Type": "application/json"},
json={"rotate_secret_key": True},
)
new_secret = r.json()["secret_shared_key"]Example — disable webhooks:
requests.patch(
"https://verification.didit.me/v3/webhook/",
headers={"x-api-key": API_KEY, "Content-Type": "application/json"},
json={"webhook_url": None},
)Response (200): Same shape as GET — returns the updated configuration.
Didit sends POST requests to your webhook URL when session status changes. Retries up to 2 times with exponential backoff (1 min, 4 min).
{
"session_id": "...",
"status": "Approved",
"webhook_type": "status.updated",
"vendor_data": "user-123",
"timestamp": 1627680000,
"decision": { ... }
}Event types: status.updated (status change), data.updated (KYC/POA data manually updated).
Two headers: X-Signature-V2 (HMAC-SHA256 hex) and X-Timestamp (Unix seconds).
import hashlib, hmac, time, json
def verify_webhook_v2(body_dict: dict, signature: str, timestamp: str, secret: str) -> bool:
if abs(time.time() - int(timestamp)) > 300:
return False
def process_value(v):
if isinstance(v, float) and v == int(v):
return int(v)
if isinstance(v, dict):
return {k: process_value(val) for k, val in v.items()}
if isinstance(v, list):
return [process_value(i) for i in v]
return v
canonical = json.dumps(process_value(body_dict), sort_keys=True, ensure_ascii=False, separators=(",", ":"))
message = f"{timestamp}:{canonical}"
expected = hmac.new(secret.encode(), message.encode(), hashlib.sha256).hexdigest()
return hmac.compare_digest(expected, signature)Header: X-Signature-Simple — HMAC of key fields only.
def verify_webhook_simple(session_id, status, webhook_type, timestamp, signature, secret):
message = f"{timestamp}:{session_id}:{status}:{webhook_type}"
expected = hmac.new(secret.encode(), message.encode(), hashlib.sha256).hexdigest()
return hmac.compare_digest(signature, expected)| Code | Meaning | Action |
|---|---|---|
400 | Invalid request | Check required fields and formats |
401 | Invalid or missing API key | Verify x-api-key header |
403 | Insufficient credits or no permission | Check balance, API key permissions |
404 | Resource not found | Verify IDs |
429 | Rate limited | Check Retry-After header, exponential backoff |
1. POST /programmatic/register/ → register
2. POST /programmatic/verify-email/ → get api_key
3. POST /v3/workflows/ → create KYC workflow
4. PATCH /v3/webhook/ → set webhook_url + webhook_version "v3"
5. POST /v3/session/ → create session → get URL
6. User completes verification at URL
7. Webhook fires → GET /v3/session/{id}/decision/ → read results1. Webhook: status "In Review"
2. GET /v3/session/{id}/decision/ → inspect results
3. If fraud: PATCH update-status → Declined + POST /v3/blocklist/add/
If legit: PATCH update-status → ApprovedService A: POST /v3/session/{id}/share/ → get share_token
Service B: POST /v3/session/import-shared/ → import with trust_review=true1. GET /v3/billing/balance/ → check if balance > 0
2. If low: POST /v3/billing/top-up/ → get Stripe checkout URL
3. POST /v3/session/ → create session1. POST /v3/questionnaires/ → create form → save uuid
2. POST /v3/workflows/ → questionnaire_verification type
3. POST /v3/session/ → session with workflow_idpip install requests
python scripts/setup_account.py register you@gmail.com 'MyStr0ng!Pass'
# (check email for code)
python scripts/setup_account.py verify you@gmail.com A3K9F2
# Prints api_key, org_uuid, app_uuid
python scripts/setup_account.py login you@gmail.com 'MyStr0ng!Pass'export DIDIT_API_KEY="your_key"
python scripts/manage_workflows.py list
python scripts/manage_workflows.py create --label "My KYC" --type kyc --liveness --face-match
python scripts/manage_workflows.py get <uuid>
python scripts/manage_workflows.py update <uuid> --enable-aml --aml-threshold 75
python scripts/manage_workflows.py delete <uuid>export DIDIT_API_KEY="your_key"
python scripts/create_session.py --workflow-id <uuid> --vendor-data user-123
python scripts/create_session.py --workflow-id <uuid> --vendor-data user-123 --callback https://myapp.com/doneAll scripts can be imported as libraries:
from scripts.setup_account import register, verify_email, login
from scripts.manage_workflows import list_workflows, create_workflow
from scripts.create_session import create_session© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (scripts) in skills/didit-verification-management of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Didit Verification Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Didit Verification Management this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~7.3k | Automated safety check: Pass | MIT | |
| Novu Design Workflownovuhq/novu | 40k | — | ~2.6k | Automated safety check: Pass | Custom licence | |
| Golivemikehasa/golive-skill | 1.3k | — | ~13k | Automated safety check: Notes | MIT | |
| Stripe Appsfossasia/eventyay | 1.7k | 1 repos | ~3.6k | Automated safety check: Pass | Apache-2.0 | |
| Dingtalk Messageagentscope-ai/ReMe | 3.6k | — | ~1.6k | Automated safety check: Pass | Apache-2.0 | |
| PR Review Provideryansongda/pay | 5.4k | — | ~2.4k | Automated safety check: Pass | MIT |
novuhq/novu
Design notification workflows the Novu way — choose channels, set severity, decide when a workflow is critical, configure digests, and route based on subscriber state.
mikehasa/golive-skill
Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).
fossasia/eventyay
A skill your agent uses when building, modifying, or reviewing a Stripe App — or when the user describes something that implies one (e.g.
agentscope-ai/ReMe
钉钉消息发送技能。支持企业内部机器人(批量单聊/群聊)和 Webhook 自定义机器人两种接入方式,支持多机器人管理,支持文本、Markdown、链接、ActionCard、FeedCard等多种消息类型。
yansongda/pay
A skill your agent uses when reviewing PRs that add or modify a payment Provider in yansongda/pay - covers plugin pipeline, multi-tenant safety, signature verification, docs, and naming conventions.
kanchengw/cnllm
Guides Stripe integration decisions — API selection (Checkout Sessions vs PaymentIntents), Connect platform setup (Accounts v2, controller properties), billing/subscriptions, Treasury financial…
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Categories
Full Didit identity verification platform management — account creation, API keys, sessions, workflows, questionnaires, users, billing, blocklist, and webhooks. Didit Verification Management is an agent skill from LeoYeAI/openclaw-master-skills. Full Didit identity verification platform management — account creation, API keys, sessions, workflows, questionnaires, users, billing, blocklist, and webhooks.
Didit Verification Management fits situations like: someone needs to create a Didit account; set up verification workflows; retrieve verification sessions; decline sessions.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a claude-code`. Or copy the skill folder (skills/didit-verification-management in LeoYeAI/openclaw-master-skills) into .claude/skills/didit-verification-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a codex`. Or copy the skill folder (skills/didit-verification-management in LeoYeAI/openclaw-master-skills) into .agents/skills/didit-verification-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill didit-verification-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/didit-verification-management, .gemini/skills/didit-verification-management, .github/skills/didit-verification-management and .opencode/skills/didit-verification-management in your project.
Going by SKILL.md and its folder, Didit Verification Management needs Python for the scripts in its folder, the command-line tools its instructions call (python and pip) and credentials named API_KEY and DIDIT_API_KEY. Our summary lists: Python 3; A credential in DIDIT_API_KEY; A credential in API_KEY.
SKILL.md names 6 domains. In commands or code: verification.didit.me, apx.didit.me, verify.didit.me and checkout.stripe.com; the agent is likely to contact these when it follows the instructions. As links in the text: docs.didit.me and business.didit.me. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Didit Verification Management is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 7.3k tokens (SKILL.md is roughly 29k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Didit Verification Management: Novu Design Workflow (novuhq/novu, 40k stars), Golive (mikehasa/golive-skill, 1.3k stars), Stripe Apps (fossasia/eventyay, 1.7k stars) and Dingtalk Message (agentscope-ai/ReMe, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,161 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.