Skip to content

Crypto exchanges

Know who is on the other side of the order book.

Exchanges onboard people from many countries and must screen them against sanctions lists. KYCVerify reads any ICAO 9303 document, checks liveness and face match, screens OFAC SDN and UN lists, and catches the same face opening a second account.

Recommended workflowCrypto exchanges
  1. 1Consent
  2. 2Email OTP
  3. 3Document (passport, ID card, residence permit)
  4. 4Liveness

At submit

  • Face match
  • AML screening
  • Age (18+)
  • Duplicate detection
  • IP capture
sanctions lists, screened on every name
2
liveness challenges per attempt
4
MRZ layouts read
6

decision.auto_decline: true · a failed check declines

The problem

What this use case needs from verification.

  • Global documents

    Passports and ID cards from any issuer are read through the MRZ, with check digits and expiry enforced, and the issuing country restricted when you need to.

  • Sanctions exposure

    Every verified name is screened against OFAC SDN with aliases and the UN consolidated list. Potential matches always reach a human.

  • Multi-accounting

    Document fingerprints and face embeddings flag the same person behind a second account for review.

Recommended workflow

Steps the person sees, checks that decide.

Four challenges make each liveness attempt longer to fake; restrict `allowed_countries` to the jurisdictions you serve.

In the hosted flow

  1. 1Consent
  2. 2Email OTP
  3. 3Document (passport, ID card, residence permit)
  4. 4Liveness

At submit

  • Face match
  • AML screening
  • Age (18+)
  • Duplicate detection
  • IP capture
  • IP recorded for the audit trail

Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.

Workflow config · json
{
  "steps": {
    "email":      { "enabled": true },
    "document":   { "enabled": true, "allowed_types": ["passport", "id_card", "residence_permit"],
                    "allowed_countries": [], "reject_expired": true },
    "liveness":   { "enabled": true, "challenges": 4 },
    "face_match": { "enabled": true },
    "aml":        { "enabled": true, "match_threshold": 0.90, "review_threshold": 0.82 },
    "age":        { "enabled": true, "min_age": 18 },
    "duplicate":  { "enabled": true }
  },
  "decision": { "auto_decline": true }
}

Signals

What happens when something is off.

Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.

Signals and outcomes
WhenSeen byOutcome
A passport from a country you do not servedocumentfaileddocument_country_not_allowed
The passport has expireddocumentfaileddocument_expired
An MRZ check digit does not verifydocumentreviewdocument_mrz_invalid
A replayed photo instead of a live facelivenessattempt failsframes_identical or challenge_failed
The name scores 0.90 or more against a listed entryamlreviewaml_potential_match, severity high
The same face opens a second accountduplicatereviewduplicate_found
A sanctions list was never downloaded on the serveramlreviewaml_lists_not_loaded

Regulatory context

Where the rules meet the product.

Exchanges carry both identity and sanctions obligations, usually in more than one country. KYCVerify covers part of them. This is context, not legal advice.

Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.

  • PMLA reporting entities (India)

    Since March 2023, virtual digital asset service providers in India are reporting entities under the Prevention of Money Laundering Act and register with FIU-IND. Customer identification is one obligation among several, alongside transaction reporting KYCVerify does not do.

  • Sanctions screening

    KYCVerify screens against the OFAC SDN and UN Security Council consolidated lists. Your licence may name others (national lists, the EU consolidated list) and PEP or adverse-media checks, which need another provider.

  • FATF Recommendation 16 (Travel Rule)

    Requires originator and beneficiary information to travel with virtual-asset transfers. KYCVerify identifies your customer; it does not exchange Travel Rule data with other providers.

  • Data protection

    Whatever the jurisdiction, identity images and sanctions results are sensitive. KYCVerify encrypts uploads at rest, isolates each organisation's data and purges evidence on the retention period you set.

What KYCVerify does not settle for you

  • Screening covers OFAC SDN and the UN consolidated list only. Add PEP, adverse-media and other national lists through a separate provider if your licence requires them.
  • There is no transaction monitoring, wallet screening or Travel Rule support.

Integrate

One call starts it.

Create the session when the user starts onboarding; hold deposits until the webhook says approved.

  1. 1Create the session with this workflow and your own reference.
  2. 2Send the person the url, or open it on a device you control.
  3. 3Act on the signed session.status_updated webhook.

Create a session

curl -X POST https://kycverify.me/api/v1/sessions \
  -H "x-api-key: $KYC_API_KEY" \
  -H "content-type: application/json" \
  -d '{
    "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
    "vendor_data": "acct-55120",
    "contact": {
      "email": "trader@example.com"
    },
    "metadata": {
      "tier": "standard",
      "region": "eu"
    }
  }'

201 Created

{
  "session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
  "status": "not_started",
  "url": "https://kycverify.me/verify/q3Xf…",
  "session_token": "q3Xf…",
  "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
  "vendor_data": "acct-55120",
  "expires_at": "2026-10-10T09:12:44Z"
}

FAQ

Questions.

Can we block certain countries?

Set allowed_countries on the document step. A document from any other issuer is refused before an attempt is spent.

Build this workflow in the sandbox.

Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.