Skip to content

Product

From consent to a signed decision, with the evidence.

A hosted flow collects what the workflow asks for, the Rust engine runs each check, a documented rule decides, and a signed webhook tells your backend. Here is every piece.

Example decision

ses_01JD7Q8YB6N2Z3K4M5P6R7S8T9

In review
  • documentTD3 · check digits validPassed
  • livenessturn_left · smile · move_closerPassed
  • face_matchthreshold 0.363 · reference documentPassed
  • amlpotential_match · ofac_sdnNeeds review
  • duplicate1 fingerprint · 1 face comparedPassed
  • ipip and user agent recordedPassed
Decision reason aml_potential_match · a hit alone never fails the AML check
An example session in review: document, liveness, face match, duplicate and IP checks passed; the AML check found a potential match and sent the session to review.

Built on standards

Named standards, not a black box.

Each check implements something you can look up. Where a model is involved, it is an openly licensed one, run in-process on KYCVerify's own servers. No external model API sees an image.

Standards and primitives implemented
Standard or primitiveWhat it does hereWhere
ICAO Doc 9303Machine-readable zones: 6 layouts, 7-3-1 check digitsDocument verification
UIDAI Secure QR (2019) and Offline e-KYCRSA SHA256withRSA and enveloped XML-DSig, verified with UIDAI's certificateAadhaar
Verhoeff checksumAadhaar numbers read from a card by OCRDocument verification
Income Tax Department PAN formatStructure, holder type and name initialPAN
OFAC SDN and UN consolidated listsDownloaded from the official sources into an in-memory indexAML screening
YuNet and SFace (OpenCV model zoo)Face detection, landmarks and 1:1 embeddings, run on your CPULiveness, Face match
HMAC-SHA256Webhook signatures over timestamp and raw bodyWebhooks and API
AES-256-GCMEvery uploaded file, encrypted at restSecurity
Argon2idConsole passwordsSecurity

The hosted flow

Seven positions, always in the same order.

A workflow chooses which steps appear; the order never changes, so the experience is predictable for people and for your support team.

  1. 01ConsentThe person accepts the processing notice for your app.
  2. 02EmailOptional one-time code: 6 digits, valid 10 minutes.
  3. 03DocumentType, country, front and back, with a quality gate.
  4. 04AadhaarSecure QR or Offline e-KYC, signature verified.
  5. 05PANNumber, name and an optional card photo.
  6. 06LivenessRandom challenges, analysed frame by frame.
  7. 07SubmitBackground checks run and a decision is reached.

Checks

Ten check kinds, two moments.

Steps write their checks as the person goes. Background checks run once, at submit, from what the steps collected.

  1. 01

    Any check failed

    The session is declined, or sent to review when the workflow turns auto-decline off.

  2. 02

    Else any check in review or error

    The session goes to the review queue for a person to decide.

  3. 03

    Else

    The session is approved.

During the flow

  • Documentdocument
  • Livenessliveness
  • Aadhaaraadhaar
  • PANpan
  • Emailemail

At submit

  • Face matchface_match
  • AMLaml
  • Ageage
  • Duplicateduplicate
  • IPip

The checks, in depth

Know exactly what each check proves, and what it does not.

Every check writes a status, a score where one exists, and the warnings behind it. Defaults below are the shipped workflow configuration; every limit is stated next to the feature.

ICAO 9303 · 7-3-1

Read the document the way the issuer wrote it.

Passports, ID cards and residence permits through the ICAO 9303 MRZ; Indian cards through OCR.

Check digits
Document number, date of birth, expiry, optional data and the composite digit, each recomputed with ICAO's 7-3-1 weights. Long TD1/TD2 document numbers that continue into the optional field are handled.
OCR correction you can see
Common confusions (O and 0, I and 1) are corrected only in positions whose alphabet is known, and every correction is reported, so a reviewer can tell a clean read from a repaired one.
Image quality
Resolution, sharpness (variance of the Laplacian), exposure and glare are measured first. A blurry or glare-washed capture is sent back to the person with a reason instead of being guessed at.
Expiry, type and country
An expired document is declined when the workflow says so. The declared type and issuing country must match what the MRZ says, and the country must be on the workflow's allow-list.

Stated plainly: No NFC chip reading: the e-passport chip is not read, so the check relies on the printed MRZ and the image.

Document verification in detail

Workflow configuration · defaults

allowed_types
Which document types the person may choose.
all 7
allowed_countries
ISO 3166-1 alpha-3 issuing countries, e.g. IND, GBR.
[] (any)
reject_expired
Decline a document past its expiry date.
true
max_attempts
Captures allowed before the step fails.
3
A document check on the ICAO specimen passport · json
{
  "kind": "document",
  "status": "failed",
  "score": 1.0,
  "data": {
    "document_type": "passport",
    "country": "UTO",
    "attempt": 1,
    "issuing_country": "UTO",
    "verification_level": "mrz_check_digits",
    "mrz": {
      "format": "td3", "document_code": "P", "issuing_state": "UTO", "valid": true,
      "check_digits": { "document_number": true, "birth_date": true, "expiry_date": true,
                        "optional_data": true, "composite": true },
      "corrections": 0
    },
    "reason": "document_expired"
  },
  "warnings": [
    { "code": "document_expired", "message": "The document expired on 2012-04-15", "severity": "high" }
  ]
}

FAQ

What people ask before they integrate.

Is KYCVerify a hosted service?

Yes. KYCVerify runs at kycverify.me: your backend calls https://kycverify.me/api, people verify at kycverify.me/verify/{token}, and your team uses the console there. Every check runs on KYCVerify's own engine, uploads are encrypted at rest with AES-256-GCM, and each app's evidence is purged after its retention period.

What can it verify?

Passports, ID cards and residence permits through the ICAO 9303 MRZ; Aadhaar, PAN, voter ID and Indian driving licences by OCR; Aadhaar Secure QR and Offline e-KYC against UIDAI signatures; active liveness; face match; sanctions screening against OFAC SDN and UN lists; minimum age; duplicates; email ownership.

What does it not do?

No NFC chip reading, no certified passive liveness, no PEP or adverse-media screening, no KYB, no phone OTP, no government database lookups and no native SDKs. We would rather you know now. The comparison lists it all.

Is the liveness check certified?

No. It is active challenge-response (turn left, turn right, smile, move closer) analysed frame by frame on KYCVerify's engine, and it is labelled as such. It has not been tested by a presentation-attack-detection lab.

How does my backend get the result?

A session.status_updated webhook signed with HMAC-SHA256 for every status change, carrying the full decision when the session is final. You can also call GET /v1/sessions/{id}/decision at any time.

Do people need to install an app?

No. The hosted flow runs in the browser on any modern phone or laptop and uses the device camera.

How long is data kept?

Each app has a retention period, 90 days by default. A worker purges the files, face embeddings and identity data of older sessions automatically, and you can purge any session on demand with DELETE /v1/sessions/{id}.

Does it handle Aadhaar numbers?

The offline formats (Secure QR and Offline e-KYC XML) contain only the last four digits, so that is all they give you. If a workflow also accepts a photographed Aadhaar card, the number is read to validate it and kept only masked and as a keyed fingerprint; the card image, which shows the full number, stays encrypted until the retention purge.

Try every check in the sandbox.

Sign up for an organisation with a sandbox app, test keys and a default workflow.