Developers
Build on Karibu ID
Karibu ID’s API is the same contract its own apps use. This guide is built from that contract (version 0.59.0); the contract itself is the reference.
Karibu ID reports findings, never verdicts. Nothing the API returns grades, ranks or predicts a company or a person, and no fee depends on a finding, a policy result or a deal.
The guide
- Connect and the reader APITwo ways in: the reader API for your own organisation’s work, and Connect for a platform acting under a company’s grant.
- AuthenticationOpenID Connect through Karibu ID’s identity service (Keycloak), bearer access tokens, and a passkey for sensitive actions. There are no API keys.
- WebhooksEvents by HTTPS POST, ids only, signed with HMAC-SHA256 and retried for 24 hours.
- Rate limitsLimits per caller and route class, announced in RateLimit headers.
- Versioning and deprecationOne contract, additive within /v1, with every release in the changelog.
- The sandboxA separate environment on the demo tenant: synthetic companies, fake sources, no billing.
Integration recipes
Guides, not code, for bringing what Karibu ID holds into other tools. Karibu ID has no partnership with any of them; each name is a trademark of its owner.