Identity Verification by 1Kosmos brings government-grade identity proofing into SailPoint Identity Security Cloud.

Integration type

IGA

Overview

Identity Verification by 1Kosmos is embedded natively in SailPoint Identity Security Cloud. When a new identity is created, 1Kosmos triggers a verification session covering document capture, biometric checks, and liveness detection. Results post directly back to SailPoint to gate provisioning and satisfy compliance requirements.

What we solve

Identity governance and lifecycle workflows can be undermined when accounts and access requests are created for the wrong person, enabling impersonation and onboarding fraud. Most identity systems verify a user once at onboarding, then trust that credential for every provisioning decision that follows. This integration adds high-assurance identity verification, combining document capture, biometric matching, and liveness detection directly into SailPoint-driven joiner and access flows. Organizations can confirm the real person behind an identity before provisioning access, without a separate purchasing process or additional development work.

Prerequisites

  • Active SailPoint Identity Security Cloud tenant: The configuring administrator must have sufficient ISC permissions to create sources, configure workflows, and use the Workflow Builder.

  • 1Kosmos account: A 1Kosmos tenant is required before configuration begins. Contact 1Kosmos at 1kosmos.com/contact to initiate provisioning.

  • API credentials: Obtain your 1Kosmos API key and tenant URL from the 1Kosmos admin portal. These are required to configure the HTTP Request nodes in SailPoint Workflow Builder.

  • SailPoint Compass marketplace listing: The integration is available on the SailPoint Compass marketplace. Review the listing before beginning configuration to confirm version and support details.

Integration steps

Step 1: Create the IDV source in SailPoint ISC In SailPoint ISC, create a new source to track identity verification status. This source is how ISC records and surfaces IDV outcomes at the identity level, making verification status available to provisioning rules, certifications, and review queues.

Step 2: Configure Workflow 1 (Enrollment) In SailPoint Workflow Builder, create the enrollment workflow. This workflow triggers when an administrator creates a new identity in ISC. Configure an HTTP Request node to call the 1Kosmos Create Workflow Instance API using your API key and tenant URL. The API returns a unique session ID and verification URL. Configure the workflow to record the IDV status as PENDING in the source created in Step 1, then send the user an email containing the verification link.

Step 3: Configure Workflow 2 (Result write-back) Create a second workflow to handle the 1Kosmos callback on verification completion. Configure this workflow to receive the callback, identify the correct identity using the session ID, and call the 1Kosmos result summary API to retrieve the verification outcome. Update the IDV status in the source to COMPLETED.

Step 4: Set verification requirements In the 1Kosmos admin portal, configure the verification flow for your organization. Select the required document types, biometric checks, and liveness detection settings. Optionally, enable attribute matching to compare the first name, last name, and date of birth on the scanned document against existing SailPoint identity attributes.

Step 5: Test the enrollment flow Trigger the enrollment workflow manually using a test identity in ISC. Confirm that the 1Kosmos verification session is created, the PENDING status is recorded in the source, and the verification email is sent with a working link.

Step 6: Test the result write-back Complete a verification session using the test identity. Confirm that the 1Kosmos callback reaches SailPoint, the result summary is retrieved, and the IDV status updates to COMPLETED in the source.

Step 7: Connect IDV status to provisioning and governance With verification status available in the ISC source, configure provisioning rules, certification campaigns, or manual review queues to act on IDV outcomes. Access decisions, entitlement grants, and compliance flags can now reflect confirmed identity.

Integration notes

The integration uses standard SailPoint Workflow Builder HTTP Request nodes and requires no custom code or development resources. All verification logic runs in 1Kosmos; SailPoint receives the outcome and acts on it through your existing governance workflows. Attribute matching, document type requirements, and liveness settings are configurable per organization in the 1Kosmos admin portal. Most verification sessions complete in under two minutes.

The integration is listed on the SailPoint Compass marketplace, confirming it is certified and supported. For questions about tenant provisioning or verification configuration, contact 1Kosmos directly.



Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.