https://trust.verifyyou.com. Authorization: Bearer <secret key> on every request. Raw spec: openapi.json. Try it: Swagger UI.
Keys
Secret keys,sk_test_… and sk_live_…. Server only. Test keys see test runs; live keys see live runs. A token or session from one partition reads as nonexistent under the other.
Publishable keys (pk_*) are deprecated. Start every session server side and open it in the browser with vycheck({ session }).
Errors on every endpoint
Errors are{ "detail": "<code>" }, except 422 (schema validation, an array).
Deprecated and still served (see the OpenAPI spec):
POST /v3/keys/test.