Migrating Onfido High to Trust ID H2B
Trust ID Digital Identity High (H2B) provides identity and address verification for DBS Standard. This guide covers new High checks. Existing Onfido checks retain their original provider, UUIDs, results endpoint and SDK-token flow. Trust ID M1A is the separate Medium integration.
Endpoints and candidate journey
| Operation | Onfido High | Trust ID H2B |
|---|---|---|
| Create | POST /api/digital-identity-high | POST /api/digital-identity-high-h2b |
| Results | GET /api/digital-identity-check-results | GET /api/digital-identity-high-h2b-results?uuid={uuid} |
| Candidate journey | Onfido SDK and SDK-token endpoint | Open data.url; no SDK token |
Use your existing bearer authentication and High enablement/pricing.
H2B has its own Trust ID catalogue entry and does not use X-Check-Version.
Do not send existing Onfido UUIDs to H2B results.
The create request uses the same candidate fields as M1A:
{
"candidate": {
"firstName": "John",
"lastName": "Doe",
"email": "john.doe@example.com"
},
"metaData": {
"yourReference": "2442ff26-cf62-4d72-8d0a-c34786335ead",
"customerName": "Example Customer",
"demoMode": true,
"sandboxMode": false
}
}
The response contains:
{
"uuid": "3f2504e0-4f89-41d3-9a0c-0305e82c3301",
"data": {
"url": "https://YOUR_API_HOST/api/trust-id-h2b-demo",
"detail": "Digital Identity Check (high) created successfully."
}
}
The top-level uuid identifies the created Access check. Use data.url, rather
than a root guestLinkUrl. In live or supplier sandbox mode this opens the
Trust ID journey, where the candidate supplies documents and address.
In demo mode it opens the H2B information page on your Supplier API host.
Results and downloads
Poll H2B results with the UUID returned by create. The response is an array
containing the check result. While status is Processing, native data and
media links are unavailable. Completed means processing has finished; it
does not mean that the identity and address passed.
The data.container object preserves the native Trust ID container structure,
including OverallStatus, DocumentContainerFieldList,
DocumentContainerValidationList and Documents. Internal fields whose names
start with __SYSTEM_ are removed from DocumentContainerFieldList.
Evaluate both:
DBSStandardOrEnhancedDigitalIdentityVerificationCheck.ValidationOutcome:4is a pass.AddressVerification.DetailedResult:Matchis a pass.
These named entries are in DocumentContainerValidationList. A different
outcome or No Match still returns Completed and requires your business
process to handle the result.
data.expired is the platform-level outcome, separate from the check status
and from the native Trust ID validation results inside data.container. It is
true only when the platform completed the check because the 14-day guest link
window passed; expired results have status: Completed and no data.container.
Do not read it as the identity verdict — that stays in the native validations
above.
The optional data.reportUrl downloads the stored PDF. Resolve it against
the Supplier API origin and send the normal bearer token. Non-demo
data.documentImages contains available images with the same authenticated
download requirement. Completion waits for media storage or exhausted retrieval
attempts; an unavailable report leaves data.reportUrl null.
Demo scenarios
Set metaData.demoMode to true and metaData.sandboxMode to false.
Sandbox is a real Trust ID environment and takes precedence over demo when
both flags are set, matching the M1A mode policy.
Select the scenario with candidate.lastName:
| Surname | Identity outcome / address | Supplied sample PDF |
|---|---|---|
HappyPath | 4 / Match | DBS H2B EU Passport |
NoMatch | 2 / No Match | H2B address no match |
Matching ignores case and surrounding spaces. Other surnames, including the
default Doe, use HappyPath. yourReference is an ordinary customer reference.
Demo results use a representative, sanitized native container and always
serialize data.documentImages: []. The exact supplied scenario PDF is
available through data.reportUrl after processing.
No candidate action is required. Opening the information page does not change the check. Demo processing completes automatically, never contacts Trust ID and is not billed. Sandbox-only and live checks do not interpret these surnames. Live billing is deferred until processing completes; demo and sandbox checks are exempt.