# 1Kosmos > 1Kosmos is a digital identity company whose BlockID platform combines identity proofing, document > and biometric verification, and passwordless / FIDO2 authentication into a single tenant-scoped > platform used across workforce, customer and citizen identity. It is Kantara-approved as a > full-service credential service provider conformant with NIST SP 800-63-3 at IAL2/AAL2, is FIDO2 > certified, holds SOC 2 Type II and ISO 27001, and holds a FedRAMP High authorization. Generated by the API Evangelist enrichment pipeline on 2026-08-05. 1Kosmos publishes no llms.txt of its own (`/llms.txt` returns 404 on every host). This file is a faithful index of what 1Kosmos does publish, plus the artifacts this profile derived from it. ## How the API is addressed There is no single `api.1kosmos.com`. BlockID is tenant-scoped: you call `https://{tenantDNS}`, resolve the tenant and community, read per-service base URLs from `GET /caas/sd`, and authenticate with an ECDSA-encrypted `licensekey` header plus your `publickey` — not a bearer token. The trial tenant used throughout the documentation is `blockid-trial.1kosmos.net`. ## APIs - [1Kosmos BlockID Platform API](https://developer.1kosmos.com/devportal/docs/): identity verification sessions, identity assurance level lookup, one-time passcodes, user management, access codes, W3C Verifiable Credentials and Presentations, IAL2 proofing workflows, reporting and metrics. 29 operations across 10 capability areas. ## Machine-readable contracts - [1Kosmos Postman Collection](https://documenter.getpostman.com/view/50203634/2sB3dHWZ1n): the only machine-readable contract 1Kosmos publishes. 31 runnable requests, with saved success and error responses. Saved verbatim at `postman/1kosmos-postman-collection.json`. - `openapi/1kosmos-blockid-openapi.yml`: OpenAPI 3.1 **derived by API Evangelist** from that collection. Not a provider artifact. 1Kosmos publishes no OpenAPI. ## Documentation - [Developer portal](https://developer.1kosmos.com/devportal) - [Getting started / SDK docs](https://developer.1kosmos.com/devportal/docs/) - [Product documentation](https://docs.1kosmos.com/productdocs/) - [OTP request](https://developer.1kosmos.com/devportal/docs/otp/request/) · [OTP verify](https://developer.1kosmos.com/devportal/docs/otp/verify/) - [IDVerify: driver license](https://developer.1kosmos.com/devportal/docs/idverify/dl/) · [passport](https://developer.1kosmos.com/devportal/docs/idverify/passport/) · [SSN](https://developer.1kosmos.com/devportal/docs/idverify/ssn/) · [face compare](https://developer.1kosmos.com/devportal/docs/idverify/face-compare/) · [face liveness](https://developer.1kosmos.com/devportal/docs/idverify/face-liveness/) - [UWL 2.0 sessions](https://developer.1kosmos.com/devportal/docs/uwl/) - [WebAuthn / FIDO2](https://developer.1kosmos.com/devportal/docs/webauthn/) - [Verifiable credentials](https://developer.1kosmos.com/devportal/docs/verifiable-credentials/overview/) - [OAuth2 / OIDC](https://developer.1kosmos.com/devportal/docs/oauth2-oidc/) - [Magic links](https://developer.1kosmos.com/devportal/docs/magiclinks/) - [Mobile SDK overview](https://developer.1kosmos.com/devportal/docs/mobile-sdk/overview/) ## SDKs First-party, distributed from GitHub — **none are published to npm, PyPI, Packagist, NuGet or Maven Central**. - [NodeJS](https://github.com/1Kosmos/nodejs-helper-files) · [Java](https://github.com/1Kosmos/java-helper-files) · [PHP](https://github.com/1Kosmos/php-helper-files) · [.NET Framework](https://github.com/1Kosmos/dotnet-helper-files) · [.NET Core](https://github.com/1Kosmos/dotnetcore-helper-files) · [Go](https://github.com/1Kosmos/gohelperfiles) - Android: `com.onekosmos.blockid.sdk:blockidsdk` from a 1Kosmos-operated Nexus repository - iOS: `pod 'BlockID'` from a credentialed private GitHub repository ## Operations - [Status page](https://status.1kosmos.com/) — incident.io, four regions (US, IN, EU, CA) - [AdminX release notes](https://docs.1kosmos.com/productdocs/docs/adminx/release-notes/) — monthly - [Compatibility matrix](https://docs.1kosmos.com/productdocs/docs/compatibility-matrix/) - [Compliance](https://www.1kosmos.com/compliance) - [GitHub organization](https://github.com/1Kosmos) - [Blog](https://www.1kosmos.com/resources/blog) · [Support](https://www.1kosmos.com/support) - [Sign up for the developer dashboard](https://developer.1kosmos.com/devportal/register/) ## API Evangelist artifacts in this profile - `authentication/1kosmos-authentication.yml` — the licensekey / publickey / X-TenantTag scheme - `scopes/1kosmos-scopes.yml` — the separate OAuth2/OIDC authorization-server surface - `conventions/1kosmos-conventions.yml` — service discovery, tenancy, paging, versioning, tracing - `errors/1kosmos-problem-types.yml` — three coexisting error envelopes, 21 real error cases - `data-model/1kosmos-data-model.yml` — Tenant → Community → User entity graph - `lifecycle/1kosmos-lifecycle.yml` · `changelog/1kosmos-changelog.yml` - `conformance/1kosmos-conformance.yml` — certifications and standards, conforming and not - `sandbox/1kosmos-sandbox.yml` — tenant-based sandbox model, hosted demos - `asyncapi/1kosmos-idverify-events.yml` — the E_IDV_* event vocabulary (pull-only, no webhooks) - `skills/` — six agent skills grounded in real operationIds - `security/1kosmos-domain-security.yml` — TLS/HSTS/DNSSEC/SPF/DMARC probe results ## Known gaps No OpenAPI, no llms.txt, no `/.well-known/` documents of any kind (no security.txt, no OIDC discovery, no api-catalog, no agent card), no MCP server, no public webhooks or AsyncAPI, no idempotency contract, no RFC 9457 problem details, no published deprecation policy or SLA, no vulnerability-disclosure program, no terms of service page, and no published pricing.