> ## Documentation Index
> Fetch the complete documentation index at: https://developers.vizito.eu/llms.txt
> Use this file to discover all available pages before exploring further.

# Fetching a visitor

> One visit in full, including the `photo` and `signature` that the list
endpoints leave out. Both are base64-encoded images.




## OpenAPI

````yaml https://vizito.eu/openapi.yaml get /visitors/{visitor_id}
openapi: 3.1.0
info:
  title: Vizito API
  version: 1.0.0
  description: |
    Read and write your Vizito visitor data over HTTPS.

    Every endpoint takes and returns JSON, and is authenticated with an API key
    created by a global admin on the Integrations page of the Backoffice.

    Almost every endpoint names a **location** — `company_id` in the API. Your
    key is pinned to a set of locations; naming one outside that set is refused
    with `403`. Start at `GET /companiesList`, the one endpoint that needs no
    location id.
  contact:
    name: Vizito support
    email: support@vizito.eu
    url: https://vizito.eu
  termsOfService: https://vizito.eu/terms
servers:
  - url: https://api.vizito.eu/api
    description: Production
security:
  - apiKey: []
tags:
  - name: Locations
    description: The locations your credential covers, and their configuration.
  - name: Visitors
    description: The visits themselves — one visitor is one visit, not a person.
  - name: Registered visitors
    description: Expected visitors — pre-register, invite, and sign in on arrival.
  - name: Hosts
    description: The people who can be visited.
  - name: Visit types
    description: The sign-in flows, and the questions they ask.
  - name: Entry points
    description: The doors and desks within a location.
  - name: Agreements
    description: The documents visitors sign, and the signed PDFs that come out.
  - name: Devices
    description: The kiosks at a location.
  - name: Reporting
    description: Counters, graphs and exports.
  - name: Webhooks
    description: The endpoint Vizito calls when something happens.
paths:
  /visitors/{visitor_id}:
    parameters:
      - name: visitor_id
        in: path
        required: true
        description: The visit id.
        schema:
          $ref: '#/components/schemas/ObjectId'
    get:
      tags:
        - Visitors
      summary: Fetching a visitor
      description: |
        One visit in full, including the `photo` and `signature` that the list
        endpoints leave out. Both are base64-encoded images.
      operationId: getVisitor
      responses:
        '200':
          description: The visit.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Visitor'
        '400':
          $ref: '#/components/responses/BadRequest'
        '403':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    ObjectId:
      type: string
      pattern: ^[0-9a-fA-F]{24}$
      description: A 24-character hexadecimal id.
      example: 5f2a1b9c4d3e2f0011223344
    Visitor:
      type: object
      description: |
        One visit. Every custom field the visit type defines is also present,
        under its own `field_name`.
      additionalProperties: true
      properties:
        _id:
          $ref: '#/components/schemas/ObjectId'
        company_id:
          $ref: '#/components/schemas/ObjectId'
        first_name:
          type: string
          example: Ada
        last_name:
          type: string
          example: Lovelace
        company:
          type: string
          description: The organisation the visitor comes from.
        email:
          type: string
          format: email
        phone:
          type: string
          description: International format.
        recipient:
          type: string
          description: Name of the host being visited.
        recipient_mail:
          type: string
          format: email
        visit_type:
          $ref: '#/components/schemas/ObjectId'
        entrypoint_id:
          $ref: '#/components/schemas/ObjectId'
        known_visitor_id:
          $ref: '#/components/schemas/ObjectId'
        signed_in:
          type: string
          format: date-time
        signed_out:
          type: string
          format: date-time
          description: Absent while the visitor is still inside.
        signed_in_source:
          type: integer
          enum:
            - 0
            - 1
            - 2
          description: '`0` Backoffice or API, `1` kiosk, `2` contactless.'
        signed_out_source:
          type: integer
          enum:
            - 0
            - 1
            - 2
        approval:
          type: string
          enum:
            - pending
            - approved
            - rejected
          description: Present on visit types that screen visitors.
        safe:
          type: boolean
          description: Marked safe during an evacuation.
        agreements:
          type: array
          description: Ids of the agreements signed during this visit.
          items:
            $ref: '#/components/schemas/ObjectId'
        photo:
          type: string
          description: Base64-encoded image. Only on a single-visitor fetch.
        signature:
          type: string
          description: Base64-encoded image. Only on a single-visitor fetch.
        mod_date:
          type: string
          format: date-time
    Message:
      type: object
      properties:
        message:
          type: string
  responses:
    BadRequest:
      description: The request was understood but could not be carried out.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Message'
    Unauthorized:
      description: |
        The credential was refused, or the endpoint is off limits to API keys.
        Every refusal answers identically — see the Authentication page.
      content:
        application/json:
          schema:
            type: object
            properties:
              error:
                type: string
                example: Invalid API key
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >
        An API key issued in the Backoffice, sent as `Authorization: Bearer
        vzk_<key id>_<secret>`.

        A Microsoft Entra ID access token obtained with the client credentials

        grant is accepted on the same header. The same value is also accepted in

        an `X-API-Key` header.

````

## Related topics

- [Fetching a registered visitor](/api-reference/registered-visitors/fetching-a-registered-visitor.md)
- [Fetching the dashboard](/api-reference/reporting/fetching-the-dashboard.md)
- [Fetching statistics](/api-reference/reporting/fetching-statistics.md)
- [Fetching the current visit](/api-reference/registered-visitors/fetching-the-current-visit.md)
- [Fetching an agreement](/api-reference/agreements/fetching-an-agreement.md)
