PassID
CONNECT
Integration Flow

Sandbox · synthetic data only

Institution creates request → customer clicks "Connect with PassID" → PassID owns the entire auth & consent experience → institution receives connection_id.

1
Customer on your app
Institution's web or mobile
9:41
Bloom
Portfolio · Verified Investor
$0.00
Start building wealth today
9.5% p.a. · 14-day returns · No lock-in
Step 3 of 4 — Verify your identity
Verify to unlock investing
No forms. No document uploads. Link your PassID and start investing in under 30 seconds.
Connect with PassID
Secured by PassID · No credentials shared
2
PassID hosted UI opens
PassID redirect · customer only
9:41
PassID
CONNECT
Bloom
Requesting your PassID profile
Sign in
Enter code
Email address
amara@example.com
Password
••••••••••••
Continue →
or
Open your PassID app, tap Generate Code, and enter the 6-digit code to sign in without a password.
3
Customer reviews & approves
PassID hosted consent
9:41
SANDBOX · synthetic data only
Bloom
Verified institution · PassID Connect
Bloom is requesting access to verify your identity and income to unlock your investment account.
Identity
Verified name, country, date of birth
Income
Monthly income and employer
Accounts
Bank names and masked numbers
Verification
PassID identity status
Access
90 days
Revocable
Any time
Decline
Authorize →
No bank credentials shared · PassID 2026
4
PassID processing
Automatic · zero institution input
9:41
PassID Connect
Completing authorization…
Securely linking your PassID profile to Bloom
Identity verified
Consent recorded
Creating connection…
Redirecting you back
5
Back on your app
Institution receives connection_id
9:41
Bloom
PassID verified
Identity & income confirmed. You're ready to start investing.
Connection ID
pic_sandbox_x7y8z9a1
identity.read
income.read
accounts.read
Backend now fetches
GET
/connections/pic_.../identity
GET
/connections/pic_.../income
GET
/connections/pic_.../accounts
Disconnect
Start Investing →
Institution backend · 2 API calls
POST /connect/sessions
  → hosted_url
// redirect customer there

GET  /connect/sessions/:id
  → verify callback
GET  /connect/connections/:id/identity
  → approved scoped data
PassID handles everything else
Customer authentication
Identity verification
Consent display & recording
Scope enforcement
Redirect with connection_id
Webhook delivery
Never required from institution
Staff enter PassID codes
Institution sees credentials
Manual copy-paste by agent
Institution contacts customer
Data shared without consent
Bank credentials exposed