> ## Documentation Index
> Fetch the complete documentation index at: https://developers.vizito.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Signing in registered visitors

> Creates a visit from each registered visitor, exactly as scanning their
QR code at the kiosk would. Somebody already inside is skipped, not
signed in twice, so the call is safe to repeat.




## OpenAPI

````yaml https://vizito.eu/openapi.yaml post /companies/{company_id}/knownvisitors/signin
openapi: 3.1.0
info:
  title: Vizito API
  version: 1.0.0
  description: |
    Read and write your Vizito visitor data over HTTPS.

    Every endpoint takes and returns JSON, and is authenticated with an API key
    created by a global admin on the Integrations page of the Backoffice.

    Almost every endpoint names a **location** — `company_id` in the API. Your
    key is pinned to a set of locations; naming one outside that set is refused
    with `403`. Start at `GET /companiesList`, the one endpoint that needs no
    location id.
  contact:
    name: Vizito support
    email: support@vizito.eu
    url: https://vizito.eu
  termsOfService: https://vizito.eu/terms
servers:
  - url: https://api.vizito.eu/api
    description: Production
security:
  - apiKey: []
tags:
  - name: Locations
    description: The locations your credential covers, and their configuration.
  - name: Visitors
    description: The visits themselves — one visitor is one visit, not a person.
  - name: Registered visitors
    description: Expected visitors — pre-register, invite, and sign in on arrival.
  - name: Hosts
    description: The people who can be visited.
  - name: Visit types
    description: The sign-in flows, and the questions they ask.
  - name: Entry points
    description: The doors and desks within a location.
  - name: Agreements
    description: The documents visitors sign, and the signed PDFs that come out.
  - name: Devices
    description: The kiosks at a location.
  - name: Reporting
    description: Counters, graphs and exports.
  - name: Webhooks
    description: The endpoint Vizito calls when something happens.
paths:
  /companies/{company_id}/knownvisitors/signin:
    post:
      tags:
        - Registered visitors
      summary: Signing in registered visitors
      description: |
        Creates a visit from each registered visitor, exactly as scanning their
        QR code at the kiosk would. Somebody already inside is skipped, not
        signed in twice, so the call is safe to repeat.
      operationId: signInRegisteredVisitors
      parameters:
        - $ref: '#/components/parameters/companyId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: array
              items:
                $ref: '#/components/schemas/ObjectId'
      responses:
        '200':
          description: One result per id, carrying the new visit id on success.
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
                  properties:
                    id:
                      $ref: '#/components/schemas/ObjectId'
                    status:
                      type: string
                      enum:
                        - success
                        - skipped
                        - error
                    visitorId:
                      $ref: '#/components/schemas/ObjectId'
                    reason:
                      type: string
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Unauthorized'
components:
  parameters:
    companyId:
      name: company_id
      in: path
      required: true
      description: The location.
      schema:
        $ref: '#/components/schemas/ObjectId'
  schemas:
    ObjectId:
      type: string
      pattern: ^[0-9a-fA-F]{24}$
      description: A 24-character hexadecimal id.
      example: 5f2a1b9c4d3e2f0011223344
    Message:
      type: object
      properties:
        message:
          type: string
  responses:
    BadRequest:
      description: The request was understood but could not be carried out.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Message'
    Unauthorized:
      description: |
        The credential was refused, or the endpoint is off limits to API keys.
        Every refusal answers identically — see the Authentication page.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                example: Invalid API key
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >
        An API key issued in the Backoffice, sent as `Authorization: Bearer
        vzk_<key id>_<secret>`.

        A Microsoft Entra ID access token obtained with the client credentials

        grant is accepted on the same header. The same value is also accepted in

        an `X-API-Key` header.

````

## Related topics

- [Signing in a visitor](/api-reference/visitors/signing-in-a-visitor.md)
- [Signing a visitor in and out](/documentation/signing-in-a-visitor.md)
- [Signing out a visitor](/api-reference/visitors/signing-out-a-visitor.md)
- [Signing out several visitors](/api-reference/visitors/signing-out-several-visitors.md)
- [Core concepts](/documentation/concepts.md)
