> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handles `GET /v1/control/verification-sessions/{session_id}`.

> # Errors

Returns `401` without a session, `403` for an API key or a role without
`VERIFICATIONS_READ`, `404` for a session this tenant does not have -
another tenant's and a nonexistent one answer alike - and `503` when a
store cannot be reached.



## OpenAPI

````yaml /openapi.json get /v1/control/verification-sessions/{session_id}
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers:
  - url: https://qa.esectra.com
    description: Esectra QA Documentation
security: []
paths:
  /v1/control/verification-sessions/{session_id}:
    get:
      tags:
        - Control
      summary: Handles `GET /v1/control/verification-sessions/{session_id}`.
      description: |-
        # Errors

        Returns `401` without a session, `403` for an API key or a role without
        `VERIFICATIONS_READ`, `404` for a session this tenant does not have -
        another tenant's and a nonexistent one answer alike - and `503` when a
        store cannot be reached.
      operationId: get_handler
      parameters:
        - name: session_id
          in: path
          description: The session id
          required: true
          schema:
            type: string
      responses:
        '200':
          description: The session, its checks and its resolved decision
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/HostedSessionDetail'
        '401':
          description: No usable credentials
        '403':
          description: An API key, or a role without VERIFICATIONS_READ
        '404':
          description: Not one of this tenant's sessions
        '503':
          description: A backing store could not be reached
      security:
        - session_cookie: []
components:
  schemas:
    HostedSessionDetail:
      allOf:
        - oneOf:
            - type: object
              description: One session, as a row of the listing.
              required:
                - session_id
                - subject_id
                - intent
                - status
                - created_at
                - expires_at
              properties:
                completed_at:
                  type:
                    - string
                    - 'null'
                  description: When the session concluded. Absent while it is open.
                created_at:
                  type: string
                  description: When the session was opened.
                decision:
                  oneOf:
                    - type: 'null'
                    - $ref: '#/components/schemas/Decision'
                      description: That decision's outcome, read from the decision store.
                decision_id:
                  type:
                    - string
                    - 'null'
                  description: The decision the session produced, once it has.
                expires_at:
                  type: string
                  description: When the capture link stops working.
                intent:
                  type: string
                  description: '`FIRST_TIME` or `REVERIFICATION`.'
                review_case_id:
                  type:
                    - string
                    - 'null'
                  description: >-
                    The review case opened for the decision, read from the case
                    store.
                risk_level:
                  oneOf:
                    - type: 'null'
                    - $ref: '#/components/schemas/RiskLevel'
                      description: >-
                        That decision's risk level, read from the decision
                        store.
                session_id:
                  type: string
                  description: >-
                    The session id, which the capture link and the webhook both
                    carry.
                status:
                  type: string
                  description: >-
                    `PENDING`, `PASSED`, `REVIEW_REQUIRED`, `FAILED` or
                    `EXPIRED`.
                subject_id:
                  type: string
                  description: The person, as the customer identifies them.
          description: The same fields the listing row carries.
        - type: object
          required:
            - reasons
            - policy_version
            - checks
          properties:
            checks:
              type: array
              items:
                $ref: '#/components/schemas/HostedSessionCheck'
              description: >-
                Every required check in policy order, then any that ran
                unrequired.
            policy_version:
              type: string
              description: The policy version whose checks this session had to satisfy.
            reasons:
              type: array
              items:
                $ref: '#/components/schemas/HostedSessionReason'
              description: >-
                Why the decision was what it was, from the decision store,
                reworded.
      description: One session in full.
    Decision:
      type: string
      description: Decision emitted by an automated or human-assisted workflow.
      enum:
        - ALLOW
        - WARN
        - BLOCK
        - HOLD
        - REVIEW_REQUIRED
        - FLAG
        - BLOCK_RECOMMENDED
        - SUSPEND
        - END_STREAM
    RiskLevel:
      type: string
      description: Explainable risk level.
      enum:
        - LOW
        - MEDIUM
        - HIGH
        - CRITICAL
    HostedSessionCheck:
      type: object
      description: One check of a session.
      required:
        - check
        - required
        - outcome
      properties:
        check:
          type: string
          description: Which check, as `CheckKind` codes it.
        detail:
          type:
            - string
            - 'null'
          description: |-
            What the check concluded, in a sentence written here from the check
            kind, its outcome and its reason code - never the stored prose.
        observed_at:
          type:
            - string
            - 'null'
          description: When it was performed.
        outcome:
          type: string
          description: |-
            `PASS`, `REVIEW`, `FAIL`, `ERRORED`, `SKIPPED`, or `PENDING` when it
            has not run.
        reason_code:
          type:
            - string
            - 'null'
          description: |-
            Stable reason code, once the check has run. One of the codes this
            service issues; anything else stored is reported as `UNSPECIFIED`.
        required:
          type: boolean
          description: Whether the tenant's policy required it.
    HostedSessionReason:
      type: object
      description: |-
        Why the decision was what it was.

        The code is the decision store's, when it is one this module knows; the
        message is this module's own wording for it. The stored message is never
        repeated, because the fusion writes check detail into it.
      required:
        - code
        - message
      properties:
        code:
          type: string
          description: >-
            Stable reason code, or `UNSPECIFIED` for one this module does not
            know.
        message:
          type: string
          description: Customer-safe wording of that code.
  securitySchemes:
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````