Methods to validate holder data, enroll disposable certificates, and send OTP codes.
Lean Disposable Services (26.1.0.3)
REST API for enrolling and managing lean disposable certificates for secure digital signatures.
Authenticate every request with Basic Auth credentials and a client SSL certificate (mTLS). All requests require the Content-Type: application/json header.
For the full integration guide, see the Lean Disposable documentation.
Request
Retrieves AWS credentials for the specified LRA and service. Used when a video identification process stores evidence on AWS. See getAwsParameter.
- Production environmenthttps://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getAwsParameter
- Development and testing environmenthttps://lean.test.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getAwsParameter
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
curl -i -X GET \
-u <username>:<password> \
'https://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getAwsParameter?serviceId=string'{ "serviceId": "SERVICE_NAME", "arn": "arn:aws:iam::000000000000:role/ExampleRole", "accessKey": "AKIAIOSFODNN0EXAMPLE", "secretAccessKey": "wJalrXUtnFEMI0K7MDENG0bPxRfiCYEXAMPLEKEY" }
Request
Returns the disposable contract (Mod_NAMCA22D), the privacy document URL, and the T&C document URL for the specified LRA.
The contract is pre-filled with holder data if disposableHolder, disposableContacts and disposableDoc are all provided. If omitted, the contract is returned blank.
Languages of the document. ISO 639-1 alpha-2 codes. You can specify more than one value.
Type of document to return. 1 = PDF, 2 = TXT. You can specify more than one value.
Country where the end user is located. ISO 3166-1 alpha-2 code. Optional — if not specified, the default template for the given languageCode is returned. Required when a LRA needs contracts in the same language but for different legislations (e.g. French contract for France vs Belgium).
Holder data. Optional — if provided together with disposableContacts and disposableDoc, the contract (Mod_NAMCA22D) is pre-filled.
Holder contact information. Required if otpType=SMS or otpType=EMAIL. Provide mobile if otpType=SMS, email if otpType=EMAIL.
Identity document information.
Not required if one of the following conditions is true:
DisposableIdentification.identificationTypeisAMLDisposableHolder.identificationTypeis one of:PASSPORT,PERSONAL_NUMBER,NATIONAL_IDENTITY_CARD,DRIVING_LICENSE,RESIDENCE_PERMIT,RESIDENCE_PERMIT_TEMP,EMBASSY_DOCUMENT
- Production environmenthttps://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getDisposableContract
- Development and testing environmenthttps://lean.test.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getDisposableContract
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
- PDF only — blank contract (no holder data)
- PDF and TXT — blank contract
- PDF — pre-filled contract (with holder, doc and contacts)
curl -i -X POST \
-u <username>:<password> \
'https://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getDisposableContract' \
-H 'Content-Type: application/json' \
-d '{
"languageCode": [
"EN"
],
"docTypes": [
1
],
"productType": "DISPOSABLE"
}'OK
Base64-encoded document (Mod_NAMCA22D). Pre-filled with holder data if disposableHolder, disposableContacts and disposableDoc were provided in the request.
URL to download the privacy document (Mod_NAMGDPR03D).
URL to download the terms and conditions document (Mod_NAMCA01D).
List of checkbox label strings to be displayed to the user for acceptance.
- PDF only — blank contract
- PDF and TXT — blank contract
- PDF — pre-filled contract (holder data embedded in document)
[ { "languageCode": "EN", "docTypes": 1, "doc": "<base64-encoded PDF>", "privacy_link": "https://docs.namirialtsp.com/documents/Mod_NAM_GDPR03D_ENG_IT.pdf", "termsAndConditions_link": "https://docs.namirialtsp.com/documents/Mod_NAM_CA01D_ENG_IT.pdf", "checkBoxes": [ … ] } ]
Request
Retrieves disposable contract documents (Mod_NAMCA22D) using an eID assertion. Returns contract PDF/TXT, privacy document URL (Mod_NAMGDPR03D), and T&C document URL (Mod_NAMCA01D). The contract is pre-filled if eIDAssertionHolder and contacts are provided. See getDisposableContractWitheIDAssertion and How to enroll with eID assertion.
eID assertion holder data. The country and eIDType together identify the eID method (e.g., IT-SPID, IT-EIDNAMIRIAL, AT-EID). The assertion format depends on the eID type.
Certificate configuration. Specifies certificate type and options.
Disposable certificate type. See allowed values. Default: DISPOSABLE.
OTP delivery method. See allowed values. Default: SMS.
Holder contact information. Required if otpType=SMS or otpType=EMAIL. Provide mobile if otpType=SMS, email if otpType=EMAIL.
Languages of the document. ISO 639-1 alpha-2 codes. You can specify multiple values.
Document types. Allowed values: 1 (PDF), 2 (TXT). You can specify multiple values.
Country code where the final user is located. ISO 3166-1 alpha-2 code. Optional — if not specified, the default template for the specified languageCode is returned. Required when a LRA needs contracts in several languages but for different legislations (e.g., French contract for France vs. French contract for Belgium).
- Production environmenthttps://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getDisposableContractWitheIDAssertion
- Development and testing environmenthttps://lean.test.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getDisposableContractWitheIDAssertion
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
curl -i -X POST \
-u <username>:<password> \
'https://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/getDisposableContractWitheIDAssertion' \
-H 'Content-Type: application/json' \
-d '{
"eIDAssertionHolder": {
"country": "IT",
"eIDType": "EIDNAMIRIAL",
"assertion": "eyJnaXZlbl9uYW1lIjoiTWFyaW8iLCJmYW1pbHlfbmFtZSI6IlJvc3NpIiwicGVyc29uX2lkZW50aWZpZXIiOiJUSU5JVC1SU1NNUkE4MEEwMUg1MDFVIiwiYmlydGhfZGF0ZSI6IjE5ODAtMDEtMDEiLCJkb2NfdHlwZSI6Ik5BVElPTkFMX0lERU5USVRZX0NBUkQiLCJjb3VudHJ5IjoiSVQiLCJycF9uYW1lIjoiTmFtaXJpYWwgVGVzdCBSUCIsInJwX2lkIjoidGVzdC1ycC0wMDEiLCJvcmlnaW5hbF9hc3NlcnRpb24iOiJiYXNlNjRfZW5jb2RlZF9zYW1sX2Fzc2VydGlvbl9oZXJlIiwiaWF0IjoxNzA5NTY4MDAwfQ=="
},
"contacts": {
"mobile": "+390000000000",
"email": "example@example.com"
},
"cert": {
"type": "DISPOSABLE",
"password": "Password01",
"securityCode": "Security01",
"withoutUsageLimitLRA": false
},
"languageCode": [
"EN"
],
"docTypes": [
1
]
}'Contract documents retrieved successfully. Returns an array of contract documents (Mod_NAMCA22D) with privacy and T&C links. The contract is pre-filled if eIDAssertionHolder and contacts are provided.
Base64-encoded document (Mod_NAMCA22D). Pre-filled with holder data if disposableHolder, disposableContacts and disposableDoc were provided in the request.
URL to download the privacy document (Mod_NAMGDPR03D).
URL to download the terms and conditions document (Mod_NAMCA01D).
List of checkbox label strings to be displayed to the user for acceptance.
[ { "languageCode": "IT", "docTypes": 2, "doc": "string", "privacy_link": "https://docs.namirialtsp.com/documents/Mod_NAM_GDPR03D_ITA_IT.pdf", "termsAndConditions_link": "https://docs.namirialtsp.com/documents/Mod_NAM_CA01D_ITA_IT.pdf", "checkBoxes": [ … ] } ]
Request
Associates an AWS identification reference to an issued disposable certificate. Used when a video identification process stores evidence on AWS.
See uploadAwsId.
AWS identification reference for the video identification evidence.
Device code of the issued certificate, returned by enroll (deviceCode).
OTP certificate identifier returned by enroll (certIdOtp).
- Production environmenthttps://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/uploadAwsId
- Development and testing environmenthttps://lean.test.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/uploadAwsId
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
curl -i -X POST \
-u <username>:<password> \
'https://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/uploadAwsId' \
-H 'Content-Type: application/json' \
-d '{
"awsId": "HgI1MM8VuxpoXh6xozcd0gU8rPCvUN6c9HJRY27-K9A2hRm9ZVFFsVx2whuohH63",
"deviceCode": "RHIDP0000000000000",
"idOtp": 1234567,
"externalKey": "external_key_sample"
}'Request
Stores a document linked to an issued disposable certificate. Supported document types: identification evidence, signed contracts (e.g. CA22D), audit logs, identity assertions.
Note: if the disposable was issued with enrollDisposableWitheIDAssertion, the assertion is stored automatically — do not upload it with this method.
See uploadDoc.
Device code of the issued certificate, returned by enroll (deviceCode).
OTP certificate identifier returned by enroll (certIdOtp). Use 0 if the disposable has otpType=NO_OTP.
Type of document to upload.
File extension (not case-sensitive). Allowed values: pdf, zip, png, jpeg, jpg, docx, doc, odt, xml, json, txt, mp4, m4a, m4v.
- Production environmenthttps://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/uploadDoc
- Development and testing environmenthttps://lean.test.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/uploadDoc
- curl
- JavaScript
- Node.js
- Python
- Java
- C#
- PHP
- Go
- Ruby
- R
- Payload
- Upload a signed contract (PDF)
- Upload an identification document (JPEG)
curl -i -X POST \
-u <username>:<password> \
'https://lean.namirialtsp.com/RAWS_DISPOSABLE/api/document/{lraId}/uploadDoc' \
-H 'Content-Type: application/json' \
-d '{
"deviceCode": "RHIDP0000000000000",
"idOtp": 1234567,
"typeDoc": "CONTRACT",
"extension": "pdf",
"file": "<base64-encoded PDF>"
}'OK
Device code of the certificate the document is linked to.
Server-generated filename for the uploaded document.
Type of the uploaded document.
External reference key, if provided in the request. null if not provided.
{ "deviceCode": "RHIDP0000000000000", "filename": "1234567_a4ece4b3e9626ccfd3bac2eb77c0c1d7950be77e190a64fcf1957279e677ffc7.pdf", "typeDoc": "CONTRACT", "externalKey": null, "uploadDate": 1733496805136 }