> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.esectra.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Handles `GET /v1/control/verification-sessions/{session_id}/evidence`.

> # Errors

Returns `401` without a session, `403` for an API key or a role without
`VERIFICATIONS_READ`, `404` for a session this tenant does not have, and
`503` when a store cannot be reached.



## OpenAPI

````yaml /openapi.json get /v1/control/verification-sessions/{session_id}/evidence
openapi: 3.1.0
info:
  title: Esectra API
  description: >-
    Transaction screening, identity verification, and wallet risk.


    Every create route accepts `Idempotency-Key`; replaying one returns the
    original record with `200` where the first call returned `201`. `POST
    /v1/transactions` requires the header, because a duplicated transaction is a
    duplicated financial record.
  license:
    name: proprietary
    identifier: proprietary
  version: 0.1.0
servers: []
security: []
paths:
  /v1/control/verification-sessions/{session_id}/evidence:
    get:
      tags:
        - Control
      summary: Handles `GET /v1/control/verification-sessions/{session_id}/evidence`.
      description: |-
        # Errors

        Returns `401` without a session, `403` for an API key or a role without
        `VERIFICATIONS_READ`, `404` for a session this tenant does not have, and
        `503` when a store cannot be reached.
      operationId: session_evidence_handler
      parameters:
        - name: session_id
          in: path
          description: The session id
          required: true
          schema:
            type: string
      responses:
        '200':
          description: >-
            What was submitted and how it was read. No image bytes, no evidence
            identifiers.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EvidenceBody'
        '401':
          description: No usable credentials
        '403':
          description: An API key, or a role without VERIFICATIONS_READ
        '404':
          description: Not one of this tenant's sessions
        '503':
          description: A backing store could not be reached
      security:
        - session_cookie: []
components:
  schemas:
    EvidenceBody:
      type: object
      description: One kind of evidence and how far it got, as a customer sees it.
      required:
        - kind
        - state
        - usable
      properties:
        detail:
          type:
            - string
            - 'null'
          description: Operator-facing detail, such as a correlation or an error.
        kind:
          type: string
          description: Which check.
        observed_at:
          type:
            - string
            - 'null'
          description: RFC 3339 time it was gathered, when it was.
        state:
          type: string
          description: |-
            How far it got: `PRESENT`, `PENDING`, `STALE`, `UNSUPPORTED` or
            `UNAVAILABLE`.
        usable:
          type: boolean
          description: >-
            Whether this check may contribute to clearing the transaction.


            Sent explicitly rather than left for the caller to derive from
            `state`.

            A customer's integration that had to maintain its own list of which

            states count would silently start treating a new state as passing.
  securitySchemes:
    session_cookie:
      type: apiKey
      in: cookie
      name: esectra_session
      description: >-
        A signed-in reviewer's session. httpOnly and SameSite=Lax; set by `POST
        /v1/control/sessions` and only usable once the second factor is met.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.