GET /v1/reports/{check_id}¶
Downloads the completed PDF report for a background check.
The report URL returned in GET /v1/requests/{id}
under checks[].report_pdf_url points to this endpoint and includes a
short-lived signed token (?t=...) for direct access to the report.
Request¶
GET /v1/reports/a91b34c2-0000-0000-0000-000000000000 HTTP/1.1
Host: api.xref.com
X-Xref-API-Key: <api-key>
X-Xref-User-Email: <user@yourcompany.com>
Accept: application/pdf
Path parameters¶
| Name | Type | Description |
|---|---|---|
check_id |
string (UUID) | The public check ID (checks[].id in GET /v1/requests/{id}). |
Query parameters¶
| Name | Type | Required | Description |
|---|---|---|---|
t |
string | Optional | Short-lived signed token included in report_pdf_url returned by GET /v1/requests/{id}. The token is valid for 1 hour and can be used to access the report without the standard authentication headers. |
Headers¶
| Header | Required | Description |
|---|---|---|
X-Xref-API-Key |
Conditional | Required if ?t= token query parameter is omitted. |
X-Xref-User-Email |
Conditional | Required if ?t= token query parameter is omitted. |
Accept |
No | application/pdf. |
Response¶
200 OK
| Property | Value |
|---|---|
| Content-Type | application/pdf |
| Body | Binary PDF content |
Signed report URLs¶
The report_pdf_url returned by GET /v1/requests/{id}
includes a signed t token as a query parameter:
https://api.xref.com/v1/reports/a91b34c2-0000-0000-0000-000000000000?t=123:a91b34c2-0000-0000-0000-000000000000:signature
The signed URL can be used to download the report without providing the
X-Xref-API-Key and X-Xref-User-Email headers.
The token is valid for 1 hour. After it expires, retrieve the request again
using GET /v1/requests/{id} to obtain a new
report_pdf_url.
Example request¶
Using API key and user email headers:
curl -s https://api.xref.com/v1/reports/a91b34c2-0000-0000-0000-000000000000 \
-H "X-Xref-API-Key: $XREF_API_KEY" \
-H "X-Xref-User-Email: $XREF_USER_EMAIL" \
--output background-report.pdf
Using the signed URL directly:
curl -s "https://api.xref.com/v1/reports/a91b34c2-0000-0000-0000-000000000000?t=$REPORT_TOKEN" \
--output background-report.pdf
Errors¶
| Status | status_message |
When |
|---|---|---|
401 |
client_error |
Required authentication headers are missing or invalid, or the signed t token is invalid or expired. |
403 |
client_error |
The Xref user is not an active member of the organisation associated with the API key. |
404 |
client_error |
The report could not be found, is not yet available, or is not associated with the organisation. |
429 |
client_error |
API key rate limit exceeded for requests using authentication headers. |
5xx |
server_error |
An internal server error occurred while retrieving the report. |
See Errors and status codes for more information.