Public, no sign-in; at most 10 requests a minute. Checks an uploaded certificate PDF or JSON against the stored certificate (file hash, plus the PDF signature or the JSON content) and returns authentic, tampered or revoked with a message. Returns 400 for a missing file or another file type and 404 when the file names no known certificate.
POST
/certificates/verify-document
curl \
--request POST 'http://api.example.com/certificates/verify-document' \
--header "Authorization: Bearer $ACCESS_TOKEN" \
--header "Content-Type: multipart/form-data" \
--form "file=@file"
Response examples (200)
{
"data": {
"status": "authentic",
"certificateId": "HC-2026-05-15-A1B2-1F3",
"certificateStatus": "verified",
"signaturePresent": true,
"hashMatch": true,
"documentMatch": true,
"issuedAt": "2026-05-15T09:30:00.000Z",
"message": "This document is an authentic, unmodified certificate issued by Hearsay."
},
"statusCode": 200,
"timestamp": "2026-01-15T10:15:00.000Z"
}