Skip to main content

Migrating Onfido High to Trust ID H2B

Trust ID Digital Identity High (H2B) provides identity and address verification for DBS Standard. This guide covers new High checks. Existing Onfido checks retain their original provider, UUIDs, results endpoint and SDK-token flow. Trust ID M1A is the separate Medium integration.

Endpoints and candidate journey​

OperationOnfido HighTrust ID H2B
CreatePOST /api/digital-identity-highPOST /api/digital-identity-high-h2b
ResultsGET /api/digital-identity-check-resultsGET /api/digital-identity-high-h2b-results?uuid={uuid}
Candidate journeyOnfido SDK and SDK-token endpointOpen data.url; no SDK token

Use your existing bearer authentication and High enablement/pricing. H2B has its own Trust ID catalogue entry and does not use X-Check-Version. Do not send existing Onfido UUIDs to H2B results.

The create request uses the same candidate fields as M1A:

{
"candidate": {
"firstName": "John",
"lastName": "Doe",
"email": "john.doe@example.com"
},
"metaData": {
"yourReference": "2442ff26-cf62-4d72-8d0a-c34786335ead",
"customerName": "Example Customer",
"demoMode": true,
"sandboxMode": false
}
}

The response contains:

{
"uuid": "3f2504e0-4f89-41d3-9a0c-0305e82c3301",
"data": {
"url": "https://YOUR_API_HOST/api/trust-id-h2b-demo",
"detail": "Digital Identity Check (high) created successfully."
}
}

The top-level uuid identifies the created Access check. Use data.url, rather than a root guestLinkUrl. In live or supplier sandbox mode this opens the Trust ID journey, where the candidate supplies documents and address. In demo mode it opens the H2B information page on your Supplier API host.

Results and downloads​

Poll H2B results with the UUID returned by create. The response is an array containing the check result. While status is Processing, native data and media links are unavailable. Completed means processing has finished; it does not mean that the identity and address passed.

The data.container object preserves the native Trust ID container structure, including OverallStatus, DocumentContainerFieldList, DocumentContainerValidationList and Documents. Internal fields whose names start with __SYSTEM_ are removed from DocumentContainerFieldList. Evaluate both:

  • DBSStandardOrEnhancedDigitalIdentityVerificationCheck.ValidationOutcome: 4 is a pass.
  • AddressVerification.DetailedResult: Match is a pass.

These named entries are in DocumentContainerValidationList. A different outcome or No Match still returns Completed and requires your business process to handle the result.

data.expired is the platform-level outcome, separate from the check status and from the native Trust ID validation results inside data.container. It is true only when the platform completed the check because the 14-day guest link window passed; expired results have status: Completed and no data.container. Do not read it as the identity verdict — that stays in the native validations above.

The optional data.reportUrl downloads the stored PDF. Resolve it against the Supplier API origin and send the normal bearer token. Non-demo data.documentImages contains available images with the same authenticated download requirement. Completion waits for media storage or exhausted retrieval attempts; an unavailable report leaves data.reportUrl null.

Demo scenarios​

Set metaData.demoMode to true and metaData.sandboxMode to false. Sandbox is a real Trust ID environment and takes precedence over demo when both flags are set, matching the M1A mode policy. Select the scenario with candidate.lastName:

SurnameIdentity outcome / addressSupplied sample PDF
HappyPath4 / MatchDBS H2B EU Passport
NoMatch2 / No MatchH2B address no match

Matching ignores case and surrounding spaces. Other surnames, including the default Doe, use HappyPath. yourReference is an ordinary customer reference. Demo results use a representative, sanitized native container and always serialize data.documentImages: []. The exact supplied scenario PDF is available through data.reportUrl after processing.

No candidate action is required. Opening the information page does not change the check. Demo processing completes automatically, never contacts Trust ID and is not billed. Sandbox-only and live checks do not interpret these surnames. Live billing is deferred until processing completes; demo and sandbox checks are exempt.