> ## Documentation Index
> Fetch the complete documentation index at: https://docs.docksys.xyz/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a verification session

> Creates a hosted verification session for the authenticated API key. Redirect the user to `data.verifyUrl`, then poll `GET /v2/sessions/{id}` or open the SSE stream until the session completes, expires, or is cancelled. Use `Idempotency-Key` when retrying create requests.



## OpenAPI

````yaml /api/openapi-v2.json post /v2/sessions
openapi: 3.1.0
info:
  title: Dock API v2
  version: 2.0.0
  summary: >-
    Discord to Roblox verification, account linking, alt detection, API key
    management, and bot configuration.
  description: >-
    API v2 is the recommended Dock API for new integrations. It uses consistent
    response envelopes, stable error codes, request IDs, rate-limit metadata,
    and first-class bulk endpoints.


    Use the API only for legitimate verification, moderation, analytics, and
    automation workflows. Do not scrape, bypass rate limits, rotate keys or IPs
    to avoid limits, resell the service, or use detection outputs as definitive
    proof of wrongdoing. By using Dock, you agree to the Terms of Service and
    Privacy Policy.
  termsOfService: https://docksys.xyz/terms
  contact:
    name: Dock Support
    url: https://docksys.xyz/discord
  license:
    name: Dock Terms of Service
    url: https://docksys.xyz/terms
servers:
  - url: https://api.docksys.xyz
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Lookups
    description: >-
      Read account links, verification status, and Premium alt detection
      results.
  - name: Bulk
    description: Run ordered batch lookups with per-item results.
  - name: Verification Sessions
    description: Create hosted verification sessions and read completion state.
  - name: Writes
    description: Create, update, or delete account-link data in the current API-key scope.
externalDocs:
  description: Privacy Policy
  url: https://docksys.xyz/privacy
paths:
  /v2/sessions:
    post:
      tags:
        - Verification Sessions
      summary: Create a verification session
      description: >-
        Creates a hosted verification session for the authenticated API key.
        Redirect the user to `data.verifyUrl`, then poll `GET /v2/sessions/{id}`
        or open the SSE stream until the session completes, expires, or is
        cancelled. Use `Idempotency-Key` when retrying create requests.
      operationId: postV2Session
      parameters:
        - $ref: '#/components/parameters/IdempotencyKey'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CreateSessionRequest'
            example:
              pid: PID-AB12CD34
              clientId: checkout-session-8842
              guildId: '987654321098765432'
      responses:
        '200':
          description: Verification session created or existing pending session reused.
          content:
            application/json:
              schema:
                allOf:
                  - $ref: '#/components/schemas/V2SuccessEnvelope'
                  - type: object
                    properties:
                      data:
                        $ref: '#/components/schemas/CreateSessionResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
components:
  parameters:
    IdempotencyKey:
      name: Idempotency-Key
      in: header
      required: false
      description: Unique key for safely retrying session creation requests.
      schema:
        type: string
        maxLength: 128
  schemas:
    CreateSessionRequest:
      type: object
      required:
        - pid
        - clientId
      properties:
        pid:
          type: string
          example: PID-AB12CD34
        clientId:
          type: string
          description: Developer-defined identifier for the user or flow you are verifying.
        guildId:
          type: string
          nullable: true
    V2SuccessEnvelope:
      type: object
      required:
        - status
        - data
        - meta
        - timestamp
      properties:
        status:
          type: integer
          example: 200
        data:
          description: Endpoint-specific response payload.
          nullable: true
        meta:
          $ref: '#/components/schemas/V2Meta'
        timestamp:
          type: string
          format: date-time
    CreateSessionResponse:
      type: object
      required:
        - id
        - pid
        - clientId
        - status
        - expiresAt
        - verifyUrl
        - reusedExisting
      properties:
        id:
          type: string
        pid:
          type: string
        clientId:
          type: string
        guildId:
          type: string
          nullable: true
        status:
          type: string
          enum:
            - pending
            - completed
            - expired
            - cancelled
        statusReason:
          type: string
          nullable: true
        expiresAt:
          type: string
          format: date-time
        verifyUrl:
          type: string
          format: uri
        reusedExisting:
          type: boolean
    V2Meta:
      type: object
      required:
        - requestId
        - version
        - rateLimit
      properties:
        requestId:
          type: string
          example: req_9d7b8c6a5f4e
        version:
          type: string
          example: 2.0.0
        rateLimit:
          $ref: '#/components/schemas/RateLimitMeta'
        tier:
          type: string
          enum:
            - free
            - premium
          description: Present on API-key authenticated developer endpoints.
      additionalProperties: true
    V2ErrorEnvelope:
      type: object
      required:
        - status
        - error
        - meta
        - timestamp
      properties:
        status:
          type: integer
          example: 429
        error:
          type: object
          required:
            - code
            - message
            - details
          properties:
            code:
              type: string
              example: RATE_LIMITED
            message:
              type: string
              example: Too many requests. Please retry after 1 seconds.
            details:
              nullable: true
              additionalProperties: true
        meta:
          $ref: '#/components/schemas/V2Meta'
        timestamp:
          type: string
          format: date-time
    RateLimitMeta:
      type: object
      required:
        - limit
        - remaining
        - resetAt
        - retryAfter
        - scope
      properties:
        limit:
          type: integer
          nullable: true
        remaining:
          type: integer
          nullable: true
        resetAt:
          type: string
          format: date-time
          nullable: true
        retryAfter:
          type: integer
          nullable: true
        scope:
          type: string
          nullable: true
          example: api_key
        bucket:
          type: string
          nullable: true
          example: sessions_create
  responses:
    BadRequest:
      description: The request is missing required input or contains invalid input.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V2ErrorEnvelope'
    Unauthorized:
      description: The API key is missing, invalid, expired, revoked, or suspended.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V2ErrorEnvelope'
          example:
            status: 401
            error:
              code: INVALID_API_KEY
              message: Invalid API key.
              details: null
            meta:
              requestId: req_9d7b8c6a5f4e
              version: 2.0.0
              rateLimit:
                limit: null
                remaining: null
                resetAt: null
                retryAfter: null
                scope: null
            timestamp: '2026-05-07T16:30:00.000Z'
    Forbidden:
      description: >-
        The authenticated key or session does not have access to the requested
        resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V2ErrorEnvelope'
    Conflict:
      description: The request conflicts with existing state.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V2ErrorEnvelope'
    RateLimited:
      description: >-
        Too many requests. Back off and retry after the `Retry-After` header or
        `meta.rateLimit.retryAfter` value.
      headers:
        Retry-After:
          description: Seconds to wait before retrying.
          schema:
            type: integer
        X-RateLimit-Limit:
          description: Current short-window pacing limit.
          schema:
            type: integer
        X-RateLimit-Remaining:
          description: Remaining requests in the short-window bucket.
          schema:
            type: integer
        X-RateLimit-Reset:
          description: Unix timestamp when the short-window bucket resets.
          schema:
            type: integer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V2ErrorEnvelope'
    InternalError:
      description: Dock could not complete the request.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/V2ErrorEnvelope'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: 'Dock API key. Send `Authorization: Bearer <api key>`.'

````