I Am Alive API

API reference and test bench

Endpoints marked 🔒 take an encrypted payload. The reference below documents the real model inside the payload, not { "payload": "" }, and Try it out encrypts it for you. Tokens returned by VerifyOtp and admin-verify-2fa are applied to Authorize automatically.

How an encrypted request is built

  1. Serialise the model to JSON.
  2. Encrypt that text with AES-CBC and PKCS7 padding, using the UTF-8 bytes of the server's AES_KEY and AES_IV.
  3. Base64 the ciphertext and send { "payload": "<base64>" }.

Responses are plain JSON.

Retiree verification flow

  1. POST /api/Retirees/requestOtp sends the OTP for a pension ID.
  2. POST /api/Retirees/VerifyOtp returns the bearer token.
  3. GET /api/Retirees/contact-details returns the address and next of kin to review.
  4. POST /api/Retirees/Update saves changes. Blank fields keep what's on record.
  5. POST /api/Retirees/Validate runs the selfie and BVN/NIN check.

Encryption