Integration surfaces for the identity platform.
REST APIs and mobile SDKs for embedding TrueTap credential verification, plus the integration boundaries for biometric devices, identity platforms, enterprise IAM and custom hardware. Designed for enterprise integration with structured endpoints, predictable schemas and compliance-grade logging. Access is issued only after programme qualification.
Verification endpoint
The core verification API accepts a chip identifier and challenge response, returning a structured authentication result with event identifier and metadata.
All requests are authenticated with API keys issued per programme. Responses conform to a versioned JSON schema. Endpoints are available in regional configurations to meet data residency requirements.
API and SDK access is issued only after programme qualification. Contact the team to begin the onboarding process for your integration.
Illustrative example
Core endpoints
Verify a chip
Submit a chip identifier and challenge response for authentication. Returns authenticated, tampered, or unknown with event metadata.
Retrieve chip record
Return the current status and metadata for a provisioned chip. Includes issue date, programme assignment, and lifecycle state.
Revoke a chip
Mark a chip identity as revoked. Subsequent verification attempts will return a negative result with a revoked status flag.
Audit log export
Paginated export of verification events with filter parameters by date range, chip, programme, and result type. Suitable for compliance reporting.
Webhook subscriptions
Subscribe to real-time event delivery for verification results, chip status changes, and programme lifecycle events.
iOS and Android integration
Native SDK packages for embedding TrueTap verification directly in mobile applications. Handles NFC session management, challenge construction, and result parsing.
iOS SDK
Swift package supporting iOS 13+. Integrates with CoreNFC for NFC session management. Full support for background tag reading on compatible devices.
Illustrative example
Android SDK
Kotlin/Java library for Android 8.0+. Handles NFC intent dispatch, foreground dispatch for enforcement applications, and host card emulation contexts.
Illustrative example
Beyond the verification endpoint.
The credential verification API is one surface. Programmes typically combine it with biometric-device integration, an identity or registry platform, enterprise IAM connectors, mobile verification SDKs and - where required - custom hardware integration.
Provision, verify, revoke and audit credentials
The REST surface covers the full credential lifecycle - provisioning at issuance, field verification, status and revocation management, and audit log export. Responses are versioned JSON; access is keyed per programme and rate-limited per integration.
Enrolment stations and field readers
Biometric capture devices - fingerprint, iris, face, multimodal - are integrated through device-specific SDKs and drivers supplied by the approved manufacturing partner. TrueTap defines the verification workflow and the data contract; the capture pipeline is configured to the selected device and programme requirements.
Integration boundaries and supported device profiles depend on the selected programme configuration.
Registry, deduplication and lifecycle
For national and large enterprise programmes, TrueTap integrates with the identity registry, deduplication services and lifecycle systems. Biometric matching may be performed against the sovereign identity platform or through a privacy-preserving secure-card implementation, depending on the selected architecture.
Enterprise identity providers
Integration with Microsoft Entra ID, Active Directory and enterprise IAM platforms can be delivered through appropriate connectors, SDKs and identity protocols. Integration can be delivered through appropriate identity protocols, SDKs and connectors; protocol-level support is scoped per programme rather than claimed as universal plug-and-play.
iOS and Android for field and consumer apps
Native SDK packages handle NFC session management, challenge construction, biometric capture orchestration and result parsing. Suitable for enforcement applications, workforce login apps, field officer tools and consumer verification experiences.
Custom engineering when the platform needs extending
For programmes that need custom enclosures, embedded modules, firmware integration, OEM form factors or bespoke administrative portals, custom engineering can be delivered through HSA.dev. Sovereign deployment engineering and integration with national infrastructure are scoped per programme.
Request developer access.
API credentials, SDK packages and integration support are provided to qualified programme partners. Contact the team with your integration context - credential volume, target platforms, identity systems and deployment model.