Crypto exchanges
Know who is on the other side of the order book.
Exchanges onboard people from many countries and must screen them against sanctions lists. KYCVerify reads any ICAO 9303 document, checks liveness and face match, screens OFAC SDN and UN lists, and catches the same face opening a second account.
- 1Consent
- 2Email OTP
- 3Document (passport, ID card, residence permit)
- 4Liveness
At submit
- Face match
- AML screening
- Age (18+)
- Duplicate detection
- IP capture
- sanctions lists, screened on every name
- 2
- liveness challenges per attempt
- 4
- MRZ layouts read
- 6
decision.auto_decline: true · a failed check declines
The problem
What this use case needs from verification.
Global documents
Passports and ID cards from any issuer are read through the MRZ, with check digits and expiry enforced, and the issuing country restricted when you need to.
Sanctions exposure
Every verified name is screened against OFAC SDN with aliases and the UN consolidated list. Potential matches always reach a human.
Multi-accounting
Document fingerprints and face embeddings flag the same person behind a second account for review.
Recommended workflow
Steps the person sees, checks that decide.
Four challenges make each liveness attempt longer to fake; restrict `allowed_countries` to the jurisdictions you serve.
In the hosted flow
- 1Consent
- 2Email OTP
- 3Document (passport, ID card, residence permit)
- 4Liveness
At submit
- Face match
- AML screening
- Age (18+)
- Duplicate detection
- IP capture
- IP recorded for the audit trail
Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.
{
"steps": {
"email": { "enabled": true },
"document": { "enabled": true, "allowed_types": ["passport", "id_card", "residence_permit"],
"allowed_countries": [], "reject_expired": true },
"liveness": { "enabled": true, "challenges": 4 },
"face_match": { "enabled": true },
"aml": { "enabled": true, "match_threshold": 0.90, "review_threshold": 0.82 },
"age": { "enabled": true, "min_age": 18 },
"duplicate": { "enabled": true }
},
"decision": { "auto_decline": true }
}Signals
What happens when something is off.
Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.
| When | Seen by | Outcome |
|---|---|---|
| A passport from a country you do not serve | document | faileddocument_country_not_allowed |
| The passport has expired | document | faileddocument_expired |
| An MRZ check digit does not verify | document | reviewdocument_mrz_invalid |
| A replayed photo instead of a live face | liveness | attempt failsframes_identical or challenge_failed |
| The name scores 0.90 or more against a listed entry | aml | reviewaml_potential_match, severity high |
| The same face opens a second account | duplicate | reviewduplicate_found |
| A sanctions list was never downloaded on the server | aml | reviewaml_lists_not_loaded |
Checks used
The capabilities behind it.
Each has its own page with an in-browser demo of the rule it applies.
Document verification
Passports, ID cards and residence permits through the ICAO 9303 MRZ; Indian cards through OCR.
ICAO 9303 · 7-3-1Liveness
Active challenge-response: turn left, turn right, smile, move closer, in a random order.
Active challenge-responseFace match
1:1 comparison of the selfie with the document portrait, or the Aadhaar photo.
SFace cosine · 0.363AML screening
Fuzzy name and date-of-birth matching against OFAC SDN and the UN consolidated list.
OFAC SDN · UNDuplicate detection
Flags a document or a face already seen in another verification in the same app.
Fingerprints · embeddingsWebhooks and API
Signed webhooks with persisted retries, a sessions API and standalone check endpoints.
HMAC-SHA256 · v1
Regulatory context
Where the rules meet the product.
Exchanges carry both identity and sanctions obligations, usually in more than one country. KYCVerify covers part of them. This is context, not legal advice.
Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.
PMLA reporting entities (India)
Since March 2023, virtual digital asset service providers in India are reporting entities under the Prevention of Money Laundering Act and register with FIU-IND. Customer identification is one obligation among several, alongside transaction reporting KYCVerify does not do.
Sanctions screening
KYCVerify screens against the OFAC SDN and UN Security Council consolidated lists. Your licence may name others (national lists, the EU consolidated list) and PEP or adverse-media checks, which need another provider.
FATF Recommendation 16 (Travel Rule)
Requires originator and beneficiary information to travel with virtual-asset transfers. KYCVerify identifies your customer; it does not exchange Travel Rule data with other providers.
Data protection
Whatever the jurisdiction, identity images and sanctions results are sensitive. KYCVerify encrypts uploads at rest, isolates each organisation's data and purges evidence on the retention period you set.
What KYCVerify does not settle for you
- Screening covers OFAC SDN and the UN consolidated list only. Add PEP, adverse-media and other national lists through a separate provider if your licence requires them.
- There is no transaction monitoring, wallet screening or Travel Rule support.
Integrate
One call starts it.
Create the session when the user starts onboarding; hold deposits until the webhook says approved.
- 1Create the session with this workflow and your own reference.
- 2Send the person the url, or open it on a device you control.
- 3Act on the signed session.status_updated webhook.
Create a session
curl -X POST https://kycverify.me/api/v1/sessions \
-H "x-api-key: $KYC_API_KEY" \
-H "content-type: application/json" \
-d '{
"workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
"vendor_data": "acct-55120",
"contact": {
"email": "trader@example.com"
},
"metadata": {
"tier": "standard",
"region": "eu"
}
}'201 Created
{
"session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
"status": "not_started",
"url": "https://kycverify.me/verify/q3Xf…",
"session_token": "q3Xf…",
"workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
"vendor_data": "acct-55120",
"expires_at": "2026-10-10T09:12:44Z"
}FAQ
Questions.
Can we block certain countries?
Set allowed_countries on the document step. A document from any other issuer is refused before an attempt is spent.
More solutions
Other ways teams use KYCVerify.
Fintech and lending
Borrower onboarding with Aadhaar, PAN, liveness and sanctions screening, with evidence behind every decision.
Marketplaces and gig
Verify sellers, hosts and drivers once, and stop banned users from returning.
HR onboarding
Identity checks for new hires and contractors, before day one.
Build this workflow in the sandbox.
Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.