Skip to content

GET /v1/reports/{check_id}

Downloads the completed PDF report for a background check.

The report URL returned in GET /v1/requests/{id} under checks[].report_pdf_url points to this endpoint and includes a short-lived signed token (?t=...) for direct access to the report.

Request

GET /v1/reports/a91b34c2-0000-0000-0000-000000000000 HTTP/1.1
Host: api.xref.com
X-Xref-API-Key: <api-key>
X-Xref-User-Email: <user@yourcompany.com>
Accept: application/pdf

Path parameters

Name Type Description
check_id string (UUID) The public check ID (checks[].id in GET /v1/requests/{id}).

Query parameters

Name Type Required Description
t string Optional Short-lived signed token included in report_pdf_url returned by GET /v1/requests/{id}. The token is valid for 1 hour and can be used to access the report without the standard authentication headers.

Headers

Header Required Description
X-Xref-API-Key Conditional Required if ?t= token query parameter is omitted.
X-Xref-User-Email Conditional Required if ?t= token query parameter is omitted.
Accept No application/pdf.

Response

200 OK

Property Value
Content-Type application/pdf
Body Binary PDF content

Signed report URLs

The report_pdf_url returned by GET /v1/requests/{id} includes a signed t token as a query parameter:

https://api.xref.com/v1/reports/a91b34c2-0000-0000-0000-000000000000?t=123:a91b34c2-0000-0000-0000-000000000000:signature

The signed URL can be used to download the report without providing the X-Xref-API-Key and X-Xref-User-Email headers.

The token is valid for 1 hour. After it expires, retrieve the request again using GET /v1/requests/{id} to obtain a new report_pdf_url.

Example request

Using API key and user email headers:

curl -s https://api.xref.com/v1/reports/a91b34c2-0000-0000-0000-000000000000 \
  -H "X-Xref-API-Key: $XREF_API_KEY" \
  -H "X-Xref-User-Email: $XREF_USER_EMAIL" \
  --output background-report.pdf

Using the signed URL directly:

curl -s "https://api.xref.com/v1/reports/a91b34c2-0000-0000-0000-000000000000?t=$REPORT_TOKEN" \
  --output background-report.pdf

Errors

Status status_message When
401 client_error Required authentication headers are missing or invalid, or the signed t token is invalid or expired.
403 client_error The Xref user is not an active member of the organisation associated with the API key.
404 client_error The report could not be found, is not yet available, or is not associated with the organisation.
429 client_error API key rate limit exceeded for requests using authentication headers.
5xx server_error An internal server error occurred while retrieving the report.

See Errors and status codes for more information.