> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handles `GET /v1/control/verification-sessions`.

> # Errors

Returns `401` without a session, `403` for an API key or a role without
`VERIFICATIONS_READ`, `422` for a status or decision that is not one, and
`503` when a store cannot be reached.



## OpenAPI

````yaml /openapi.json get /v1/control/verification-sessions
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/control/verification-sessions:
    get:
      tags:
        - Control
      summary: Handles `GET /v1/control/verification-sessions`.
      description: >-
        # Errors


        Returns `401` without a session, `403` for an API key or a role without

        `VERIFICATIONS_READ`, `422` for a status or decision that is not one,
        and

        `503` when a store cannot be reached.
      operationId: list_handler
      parameters:
        - name: status
          in: query
          description: One session status code.
          required: false
          schema:
            type:
              - string
              - 'null'
        - name: decision
          in: query
          description: A decision outcome; narrows to the statuses that produce it.
          required: false
          schema:
            type:
              - string
              - 'null'
        - name: subject_id
          in: query
          description: A case-insensitive fragment of the subject id.
          required: false
          schema:
            type:
              - string
              - 'null'
        - name: session_id
          in: query
          description: >-
            Exactly one session id. Finds it on any page, never another
            tenant's,

            and still subject to `status` and `decision`.
          required: false
          schema:
            type:
              - string
              - 'null'
        - name: limit
          in: query
          description: Rows per page, at most `MAX_LIMIT`.
          required: false
          schema:
            type:
              - integer
              - 'null'
            minimum: 0
        - name: cursor
          in: query
          description: The previous page's `next_cursor`.
          required: false
          schema:
            type:
              - string
              - 'null'
      responses:
        '200':
          description: This tenant's hosted sessions, newest first
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HostedSessionListBody'
        '401':
          description: No usable credentials
        '403':
          description: An API key, or a role without VERIFICATIONS_READ
        '422':
          description: An unknown status or decision filter
        '503':
          description: A backing store could not be reached
      security:
        - session_cookie: []
components:
  schemas:
    HostedSessionListBody:
      type: object
      description: A page of the listing.
      required:
        - sessions
      properties:
        next_cursor:
          type:
            - string
            - 'null'
          description: Hand back to read the next page. Absent at the end.
        sessions:
          type: array
          items:
            $ref: '#/components/schemas/HostedSessionRow'
          description: The page, newest first.
    HostedSessionRow:
      type: object
      description: One session, as a row of the listing.
      required:
        - session_id
        - subject_id
        - intent
        - status
        - created_at
        - expires_at
      properties:
        completed_at:
          type:
            - string
            - 'null'
          description: When the session concluded. Absent while it is open.
        created_at:
          type: string
          description: When the session was opened.
        decision:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/Decision'
              description: That decision's outcome, read from the decision store.
        decision_id:
          type:
            - string
            - 'null'
          description: The decision the session produced, once it has.
        expires_at:
          type: string
          description: When the capture link stops working.
        intent:
          type: string
          description: '`FIRST_TIME` or `REVERIFICATION`.'
        review_case_id:
          type:
            - string
            - 'null'
          description: The review case opened for the decision, read from the case store.
        risk_level:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/RiskLevel'
              description: That decision's risk level, read from the decision store.
        session_id:
          type: string
          description: The session id, which the capture link and the webhook both carry.
        status:
          type: string
          description: '`PENDING`, `PASSED`, `REVIEW_REQUIRED`, `FAILED` or `EXPIRED`.'
        subject_id:
          type: string
          description: The person, as the customer identifies them.
    Decision:
      type: string
      description: Decision emitted by an automated or human-assisted workflow.
      enum:
        - ALLOW
        - WARN
        - BLOCK
        - HOLD
        - REVIEW_REQUIRED
        - FLAG
        - BLOCK_RECOMMENDED
        - SUSPEND
        - END_STREAM
    RiskLevel:
      type: string
      description: Explainable risk level.
      enum:
        - LOW
        - MEDIUM
        - HIGH
        - CRITICAL
  securitySchemes:
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````