API Access & Authentication
Accessing the DVS API#
Access to the Architel Document Verification Service API is restricted to approved customers and integration partners.Before you can begin using the API, your organisation must be onboarded and issued API credentials by Architel.Your credentials will include:These credentials are used to obtain a short-lived access token.Do not include your client_secret directly in ordinary DVS verification requests.
Authentication#
The Architel DVS API uses OAuth 2.0 with the Client Credentials grant.Before calling any protected DVS endpoint, first request an access token from:Content-Type: application/x-www-form-urlencoded
grant_type=client_credentials
client_id=YOUR_CLIENT_ID
client_secret=YOUR_CLIENT_SECRET
A successful response will return an access token:{
"access_token": "YOUR_ACCESS_TOKEN",
"token_type": "Bearer",
"expires_in": 3600
}
The expires_in value indicates the lifetime of the access token in seconds.
Using the Access Token#
Once you have obtained an access token, include it in the Authorization header of all protected API requests:Authorization: Bearer YOUR_ACCESS_TOKEN
You do not need to submit your client_id or client_secret again when calling verification endpoints.
Token Expiry#
Access tokens are short-lived.When a token expires, request a new token using the same Client Credentials flow.Applications should generally obtain and reuse an access token until it expires rather than requesting a new token for every API call.If a request is made using an invalid or expired token, the API will return an authentication error.
Protecting Your Credentials#
Your client_secret must be treated as confidential.only be stored in secure server-side systems
never be embedded in browser or mobile application code
never be committed to source control
never be included in publicly accessible logs or documentation
If you believe your credentials have been exposed, contact Architel to have them replaced.
Environments#
Separate credentials may be issued for Test and Production environments.Credentials issued for one environment should not be assumed to work in another.Use the appropriate API base URL and credentials for the environment you are integrating with.
Getting API Access#
To request access to the Architel DVS API, contact Architel with:the name and contact details of the technical contact responsible for the integration
your intended use of the DVS API
whether you require Test, Production, or both environments
Once your organisation has been approved and onboarded, Architel will issue your API credentials securely.
Typical Authentication Flow#
Your Application
|
| client_id + client_secret
v
POST /oauth/token
|
| access_token
v
Your Application
|
| Authorization: Bearer <access_token>
v
DVS API
|
| verification request / result
v
Your Application
Modified at 2026-10-05 04:23:20