# Verituity > Payment integrity platform (McLean, VA) that verifies the file, the payee, the account and the > payment instruction at the moment of authorization — before money moves — across any payment rail. > Its developer-facing product is Verification-as-a-Service: one `POST /v1/verifications` call runs > up to four verification modules and returns a single normalized `decision` / `tier` / > `reason_code` response, whichever underlying data source answered. Generated by API Evangelist on 2026-09-02 from Verituity's public surface. Verituity does not publish an `/llms.txt` of its own (https://verituity.com/llms.txt returns 404), and publishes no OpenAPI, GraphQL SDL, AsyncAPI or MCP server. This file is an independent third-party summary; the authoritative source is always https://verituity.com/developers. ## What an agent can actually call One API is documented, and it is gated. - Base URL (published, sandbox/dev): `https://platform.dev.verituityplatform.com/v1` - `POST /v1/verifications` — create a verification inquiry. Live: returns HTTP 401 `{"error":"unauthorized","status":401}` with `WWW-Authenticate: Bearer realm="verification-api-dev"`. - `GET /v1/verifications/{id}` — poll an asynchronous inquiry (the `poll_url` returned on a 202). No production base URL is published anywhere. Live access is arranged through a demo request. ## Auth - Sandbox: OAuth 2.0 client-credentials machine-to-machine client (`api_client_id` + `client_secret`, secret shown once). Present the token as `Authorization: Bearer `. - Production: certificate-bound access tokens, mTLS per RFC 8705. - The token endpoint is NOT published, and neither host serves `/.well-known/oauth-authorization-server` or `/.well-known/oauth-protected-resource` (both 404), so the authorization server cannot be machine-discovered. No scope list is published. ## The request ```json { "modules": ["organization_identity", "payment_method"], "payee": { "type": "organization", "name": "...", "address": "...", "email": "...", "phone": "...", "tax_id": "...", "payment_account": {"routing_number": "...", "account_number": "..."} } } ``` Headers: `Content-Type: application/json`, `Authorization: Bearer …`, `Idempotency-Key: …`, and in sandbox `X-Sandbox-Test-Outcome` (`approve`|`review`|`deny`|`async`) and `X-Sandbox-Test-Path` (`default`|`thin_file`|`watchlist_hit`|`account_changed`). ## The response ```json { "id": "vrf_...", "object": "verification", "livemode": false, "status": "complete", "latency_ms": 214, "results": { "organization_identity": {"decision": "approve", "tier": "enhanced", "reason_code": "ORG_MATCH_CONFIRMED", "score": 0.96} }, "billing": {"test_mode": true, "billed": false, "would_bill": [{"module": "organization_identity", "tier": "enhanced", "amount": 2.50}]} } ``` **A denied payee is not an error.** A hold or a decline returns HTTP 200 with `decision: "review" | "deny"` and a `reason_code`. An agent that reads only the HTTP status will treat every blocked payee as a pass. ## Things an agent must know before calling - **Every call costs money.** Billing is per module, per inquiry: Organization Identity $1.25 basic / $2.50 enhanced, Individual Identity $1.00, Payment Method Validation $1.50 basic / $3.00 enhanced, Payee Eligibility (PQS) quoted. There is no free tier on the live API. - **The payload picks the price.** Adding `tax_id` (or `routing_number`, for organization identity) promotes a module from `basic` to `enhanced` and roughly doubles its cost. The tier is derived from what you send, not from what you subscribe to. - **Send `Idempotency-Key`.** "Idempotent retries are not re-billed." The retention window is not published, so do not assume a late retry still de-duplicates. - **Nothing here is reversible, and nothing needs to be.** The public surface creates and reads an inquiry; it does not move money and has no cancel/void/refund path. Verituity's payment orchestration (Pay) does move money, but has no public API and no documented reversal window — never infer one. - **There is no rate limit published**, no error reference beyond the 401, and no status page. Treat 4xx/5xx behaviour as unknown. - **Rehearse in sandbox first.** The outcome/path header pair deterministically forces a sanctions hit, a thin-file payee or a recently-changed bank account — the three cases that actually stop a payout — at no cost, and `would_bill[]` tells you what the same call costs live. ## Reason codes `ORG_MATCH_CONFIRMED`, `ORG_PARTIAL_MATCH`, `ORG_NO_MATCH`, `IDENTITY_CONFIRMED`, `IDENTITY_PARTIAL_MATCH`, `IDENTITY_NO_MATCH`, `ACCOUNT_OPEN_OWNER_MATCH`, `OWNER_MATCH_CONFIRMED`, `OWNERSHIP_UNVERIFIED`, `ACCOUNT_CLOSED`, `ELIGIBLE`, `MANUAL_REVIEW_REQUIRED`, `INELIGIBLE`, `LIMITED_DATA_CORROBORATION`, `WATCHLIST_POTENTIAL_MATCH`, `ACCOUNT_RECENTLY_CHANGED`. This list is not exhaustive — Verituity publishes no complete reason-code reference. ## Docs - Developer portal / API reference / getting started / rate card: https://verituity.com/developers - Verification-as-a-Service: https://verituity.com/solution-verification-as-a-service - Eligibility (PQS): https://verituity.com/pqs - Connect (file ingest, ISO 20022 normalization): https://verituity.com/connect - Detect: https://verituity.com/detect · Verify: https://verituity.com/verify · Pay: https://verituity.com/pay · Explain: https://verituity.com/explain - End-to-end payouts: https://verituity.com/solution-end-to-end-payouts - Onboarding: https://verituity.com/solution-onboarding - Newsroom: https://verituity.com/newsroom · About: https://verituity.com/about-us - Terms: https://verituity.com/terms · Privacy: https://verituity.com/privacy - Contact: info@verituity.com (sales), media@verituity.com (press) ## Compliance claimed SOC 2, PCI DSS (highest service-provider tier), NACHA account validation, ADA/WCAG, ISO 20022 normalization on ingest. No trust center, no security.txt, no vulnerability disclosure policy. ## What does not exist No OpenAPI, no GraphQL, no AsyncAPI, no MCP server, no A2A agent card, no SDK in any language, no CLI, no GitHub organization, no Postman collection, no status page, no changelog, no error reference, no published rate limits, and no self-serve signup — sandbox keys generated in the portal are explicitly non-functional examples.