AllowID developers

Work in progress. The API and SDKs work today, but AllowID is still being built: details may change before a first stable release.

SDKs and downloads

Seven languages, the same few calls in each. Free and open source under the MIT licence: use them, change them, ship them in your product.

LanguageNeedsDownload
JavaScript / TypeScript
server + web widget
Node 18+, Deno or Bun zip · 23 KB
PythonPython 3.8+zip · 6 KB
C# / .NET.NET 8, or netstandard2.0 (.NET Framework 4.6.1+)zip · 7 KB
JavaJava 11+zip · 8 KB
PHPPHP 7.4+ (uses curl when present)zip · 6 KB
GoGo 1.21+zip · 5 KB
C / C++C99 + libcurl; C++17 wrapperzip · 13 KB
All of the abovezip · 79 KB

Also: allowid-login.js (the web widget, also inside the JavaScript zip) · openapi.yaml (to generate a client for any other language) · LICENSE.

Every SDK passes the same ten end-to-end checks against the API before each release; each zip carries its own check program.

The calls§

CallDoesBilled
scan(code)What a QR reader read → who it iswhen resolved
create_session(purpose, attributes)Start a website sign-inno
get_session(id)The sign-in's outcome, on your serverfirst time authenticated
wait_for_session(id)Poll get_session until the person decidesas above
session_status(id, browser_token)Just the state, without your keyno
usage()This month's answers against your allowanceno
health()Can AllowID be reachedno
is_allowid_code(text)Is this an AllowID QR at all? No network.no

Names follow each language: createSession in JavaScript and Java, CreateSessionAsync in C#, CreateSession(ctx, …) in Go, allowid_create_session in C.

Configuration§

Every SDK reads the same two environment variables when you don't pass the values:

ALLOWID_API_KEYYour key, aidk_…
ALLOWID_BASE_URLDefault https://api.allowid.eu. Change it only when AllowID asks you to.

Timeouts default to 10 seconds. Errors are one type per language, carrying a stable code (see errors).

Per language§

import allowid

client = allowid.Client(api_key=None, base_url=None, timeout=10.0)

r = client.scan(text)                   # ScanResult(result, subject, linked, claims, repeat, usage)
r.resolved                              # result == "resolved"

s = client.create_session("Sign in to Example Co", ["profession"])
s.session_id, s.qr_payload, s.browser_token, s.expires_at

o = client.get_session(s.session_id)    # SessionResult(state, subject, claims, usage)
o = client.wait_for_session(s.session_id, timeout=180, interval=1)
o.authenticated

client.session_status(s.session_id, s.browser_token)   # "pending" | ...
client.usage()                          # Usage(month, used, included, hard_limit, licensed)
allowid.is_allowid_code(text)

try:
    client.scan(text)
except allowid.AllowIDError as e:
    e.code, e.status, e.detail, e.request_id

Another language?§

The API is plain HTTPS and JSON. HTTP API has every endpoint, and openapi.yaml generates a client for most languages.