API reference and test bench
Endpoints marked 🔒 take an encrypted payload. The reference below documents the real model
inside the payload, not { "payload": "" }, and Try it out encrypts it for you.
Tokens returned by VerifyOtp and admin-verify-2fa are applied to Authorize automatically.
How an encrypted request is built
- Serialise the model to JSON.
- Encrypt that text with AES-CBC and PKCS7 padding, using the UTF-8 bytes of the server's
AES_KEYandAES_IV. - Base64 the ciphertext and send
{ "payload": "<base64>" }.
Responses are plain JSON.
Retiree verification flow
POST /api/Retirees/requestOtpsends the OTP for a pension ID.POST /api/Retirees/VerifyOtpreturns the bearer token.GET /api/Retirees/contact-detailsreturns the address and next of kin to review.POST /api/Retirees/Updatesaves changes. Blank fields keep what's on record.POST /api/Retirees/Validateruns the selfie and BVN/NIN check.