Handles `POST /v1/verifications/result-codes/exchange`.
Spends the code atomically and answers with the session’s result. The code is bound to the caller’s tenant: another tenant’s code is unknown, not expired or spent. Every presentation is recorded, without the code.
Errors
401, 403 without VERIFICATIONS_READ, 404 RESULT_CODE_INVALID for
an unknown code, 409 RESULT_CODE_CONSUMED for one already exchanged,
410 RESULT_CODE_EXPIRED, 503 when a store cannot be reached.
Authorizations
A tenant API key. Acts for exactly one tenant and cannot conclude a case, because a conclusion records a person.
Body
A code presented for exchange.
The code from the return redirect.
Response
The session's result; the code is now spent
A hosted session's result, as the customer may read it.
Per-check results so far, worded from the check's kind, outcome and reason code; never from stored text.
RFC 3339 opening time.
FIRST_TIME or REVERIFICATION.
Why, as stable codes with customer-safe wording. A stored code this
build does not describe is UNSPECIFIED.
PENDING, PASSED, REVIEW_REQUIRED, FAILED or EXPIRED.
The person, as the customer identified them.
Session identifier.
RFC 3339 completion time, once concluded.
Its outcome.
ALLOW, WARN, BLOCK, HOLD, REVIEW_REQUIRED, FLAG, BLOCK_RECOMMENDED, SUSPEND, END_STREAM The decision, once there is one.
The flow the session ran under, when one was named.
The review case, when the outcome needs a person.
Its risk level.
LOW, MEDIUM, HIGH, CRITICAL 
