REST API
Photo workflows
people will finish.
Collect, validate, process, and export consistent portrait photos with a secure API built for real-world identity workflows.
create_invitation.sh
curl --request POST \
"https://demo.photocollect.io/apiv1/invitation" \
--header "Authorization: Custom <API_KEY>" \
--header "Content-Type: application/json" \
--data '{
"site_code": "your-site-code",
"customer_no": "12345678",
"customer_to": "user@example.com"
}'
200 OK
"invitation_key": "o2hIyfWYpMq8"The API for the complete photo lifecycle
Photo Collect is a web-based service for collecting, processing, quality-checking, and exporting portrait photos. Every setup runs on an individual domain and can support invitation-based uploads, direct uploads, a self-service kiosk, and signed Deeplinks.
| Workflow | What it does | Start here |
|---|---|---|
| Invitations | Send a personalized upload link by email or SMS, or generate a registration URL for another system to deliver. | POST /invitation |
| Direct processing | Upload an existing portrait and receive the processed image in the response. | POST /photo |
| Export polling | Retrieve approved photos in upload order, then remove them after successful storage. | GET /export |
| Deeplinks | Generate a signed, single-use upload URL without calling the API first. | Deeplink guide |
Request fundamentals
- The API is RESTful and exchanges JSON unless an endpoint documents form-encoded or binary photo data.
- Every remote request must use HTTPS. Clients must support TLS 1.2 or newer.
- HTTP/1.1 or higher is required. HTTP/1.0 is not fully supported.
- Server-to-server integrations should use a static API key in
Authorization: Custom <API_KEY>orX-Api-Key. - Successful calls return HTTP
200. Invalid input generally returns400; invalid credentials return401. - Photo uploads are limited to 60 uploads per rolling 60 seconds. Contact Photo Collect for a higher limit.
Portraits and signatures are sensitive personal data. Persist the result securely, delete exported records promptly, and apply an explicit retention policy.
Classic integration flow
- Configure the API URL, API key, and
site_codeusing Configure API in the top bar. - Create an upload invitation with
POST /invitation. - Track its state with
GET /searchor fetch the resulting image throughGET /export. - After the image is safely stored, call
DELETE /export.
The interactive console runs requests through the server. Credentials remain in the session and are never saved to a database or browser storage.