Gaming and age-restricted services
An age gate a teenager cannot click through.
Ask for a document once, check the date of birth against your minimum age, and confirm with liveness that the holder is the one on camera. Keep the result and purge the rest on your schedule.
- 1Consent
- 2Document
- 3Liveness
At submit
- Face match
- Age
- minimum age, set per workflow
- 18
- liveness challenges for a short flow
- 2
- age estimates from faces
- 0
decision.auto_decline: true · a failed check declines
The problem
What this use case needs from verification.
Real dates, not self-declared
The date of birth comes from the MRZ, the Indian card or the signed Aadhaar record, with its source recorded.
The holder, not a sibling
Liveness and face match tie the document to the person in front of the camera.
Minimal retention
Short retention periods purge the images and identity once you have the decision.
Recommended workflow
Steps the person sees, checks that decide.
Two challenges keep the flow short for a low-risk check; raise it where the stakes are higher.
In the hosted flow
- 1Consent
- 2Document
- 3Liveness
At submit
- Face match
- Age
- IP recorded for the audit trail
Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.
{
"steps": {
"document": { "enabled": true, "reject_expired": true },
"liveness": { "enabled": true, "challenges": 2 },
"face_match": { "enabled": true },
"age": { "enabled": true, "min_age": 18 },
"aml": { "enabled": false },
"duplicate": { "enabled": false }
}
}Signals
What happens when something is off.
Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.
| When | Seen by | Outcome |
|---|---|---|
| A 17-year-old uploads their own passport | age | failedage_below_minimum |
| A teenager uploads a parent's passport | face_match | failedface_match_failed |
| Only the birth year is known and it straddles 18 | age | reviewage_uncertain |
| A printed photo is held to the camera | liveness | attempt failschallenge_failed |
| The document has expired | document | faileddocument_expired |
Checks used
The capabilities behind it.
Each has its own page with an in-browser demo of the rule it applies.
Age verification
A minimum age checked against the date of birth from a verified document.
Document date of birthDocument verification
Passports, ID cards and residence permits through the ICAO 9303 MRZ; Indian cards through OCR.
ICAO 9303 · 7-3-1Liveness
Active challenge-response: turn left, turn right, smile, move closer, in a random order.
Active challenge-responseFace match
1:1 comparison of the selfie with the document portrait, or the Aadhaar photo.
SFace cosine · 0.363
Regulatory context
Where the rules meet the product.
Age assurance law is moving quickly. Here is how a document-backed check relates to the main regimes. This is context, not legal advice.
Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.
UK Online Safety Act, 2023
Requires highly effective age assurance for some services. Ofcom's guidance lists photo-ID matching (a document checked against a live image) among methods capable of being highly effective, and rules out self-declaration. Whether your implementation qualifies is your assessment.
Digital Personal Data Protection Act, 2023 (India)
Requires verifiable parental consent before processing a child's data, where a child is under 18. An age check tells you when that duty applies; collecting parental consent is outside KYCVerify.
Data minimisation
An age gate needs a yes or a no. Keep retention_days short so images and identity data are purged once the decision is made.
What KYCVerify does not settle for you
- There is no facial age estimation: every age decision needs a document or Aadhaar record with a date of birth.
Integrate
One call starts it.
Gate the restricted feature on the approved webhook, and store only the decision on your side.
- 1Create the session with this workflow and your own reference.
- 2Send the person the url, or open it on a device you control.
- 3Act on the signed session.status_updated webhook.
Create a session
curl -X POST https://kycverify.me/api/v1/sessions \
-H "x-api-key: $KYC_API_KEY" \
-H "content-type: application/json" \
-d '{
"workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
"vendor_data": "player-90211",
"metadata": {
"gate": "deposit"
},
"expires_in_hours": 24
}'201 Created
{
"session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
"status": "not_started",
"url": "https://kycverify.me/verify/q3Xf…",
"session_token": "q3Xf…",
"workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
"vendor_data": "player-90211",
"expires_at": "2026-10-04T09:12:44Z"
}FAQ
Questions.
What if only the birth year is known?
The check passes if the person is old enough on every day of that year, fails if on none, and otherwise goes to review.
More solutions
Other ways teams use KYCVerify.
Fintech and lending
Borrower onboarding with Aadhaar, PAN, liveness and sanctions screening, with evidence behind every decision.
Crypto exchanges
Passport-grade document checks and sanctions screening before the first deposit.
Marketplaces and gig
Verify sellers, hosts and drivers once, and stop banned users from returning.
Build this workflow in the sandbox.
Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.