Skip to main content

Introduction

Authenticalls is an identity verification platform. With one API key you can verify that a person is who they claim to be (KYC), match faces, estimate age, screen people against sanctions lists, look them up in national registries, extract data from identity documents and send 2FA codes.

This page explains what the platform offers, how a verification works end to end, and where to go next.

What you can do​

ProductWhat it doesStart here
KYC verificationChecks an identity document and a live selfie against each other and against the customer data you provide. Includes document authenticity checks, liveness detection and face matching.Start a new KYC session
Document analysisReads a document image and returns the detected country, document type and the extracted fields. No session needed.Analyze a document image
Data matchVerifies customer data against document images only, without a selfie.Process data match validation
Face matchCompares a reference photo with live, liveness-checked captures of the person.Face match via IFrame
Age verificationEstimates a person's age from a selfie, with an optional liveness check.Start an age verification session
National registry lookupsConfirms identity details directly with official registries (for example Nigeria NIN, BVN, passport and driving license, Kenya national ID and KRA PIN). Available standalone or as an add-on to KYC.National Registry Support Matrix
AML screeningChecks a person against sanctions and watch lists.Check person
Proof of addressExtracts the holder's address from two documents and verifies that they match.Physical address verification
Unified APIRuns several of the services above in a single request.Process Unified API session data
2FASends and verifies one-time codes by SMS or voice call.2FA API reference

How a KYC verification works​

  1. Start a session. Your backend calls Start a new KYC session with the customer's country, document type and the data you want verified (name, document number, date of birth...). You get back a session ID.
  2. Capture the document and selfie. The customer photographs their document and takes a live selfie, either in our hosted flow or in your own UI (see Ways to integrate).
  3. Process. The images and data are submitted with Process KYC session data. We check the document, run liveness detection, match the selfie to the document photo and compare the data you provided with what is printed on the document (and in the MRZ, when there is one).
  4. Get the result. The outcome is stored as a validation. You receive its ID through a redirect, a postMessage event or a signed webhook, and fetch the full result with Get KYC verdict. Results are also visible in the dashboard, and you can request a manual review of any validation.

Ways to integrate​

  • Hosted flow in your website: embed the verification in an IFrame, or open it in a new tab with a redirect back. We handle the camera, guidance and capture quality.
  • React Native apps: use the React Native SDK for a native flow.
  • Other mobile apps: load the hosted flow in a webview and receive the result through a deeplink (a Mobile Embedded integration).
  • Direct API: capture images in your own UI and call the API yourself. Every endpoint is documented in the KYC API reference.

Key concepts​

Integrations and API keys. An integration represents one of your applications (web, mobile or mobile embedded) and holds its settings, such as the trusted origin, redirect URL, webhook and branding. Each integration has its own API key, sent in the Authorization header of every request:

curl https://authenticalls.com/kyc/client/api/client-integrations/credits \
-H "Authorization: Bearer YOUR_API_KEY"

Sessions and validations. A session tracks one verification attempt from start to finish. Once a session is processed, its result is stored as a validation, with a status such as Approved or Rejected and a breakdown of every check that ran.

Credits. Operations are billed in credits. Starting a session is free: credits are only consumed when a check is processed. Paid add-ons that cannot be completed, such as a national registry lookup that fails on the registry's side, are refunded. You can check your balance at any time with Get remaining credits.

Coverage and country specific schemas. You can send documents from any country listed in the Document Support Matrix. For a growing list of countries and document types we run enhanced, country specific verification with its own set of fields. Those fields are documented per country in Countries specific schemas, and are also the fields returned by document analysis for those documents.

Get started​

  1. Create a developer account. New accounts start in trial mode with a few free checks.
  2. Create an integration and obtain an API key. Every account also includes a Playground integration for trying the flow from the developer portal.
  3. Pick an integration method from Ways to integrate and follow its guide.
  4. Use the API reference for the details of every request and response.