Liveness detection and face match API →

Know it’s really them, not just their ID.

Prove a real person is in front of the camera and match their face to their BVN, NIN, driver’s licence or voter’s card. Read and check their ID document, screen them against sanctions lists and keep watching them, and catch one face behind several accounts. One API, with libraries for Node, Python, PHP, React Native and Flutter. No developers? Send a verification link instead.

Free sandbox key · Pay only for records found · Prepaid NGN wallet

POST /v1/identity/bvn/face-match
{
"status": "verified",
"id_number": "222*****678",
"field_matches": {
"first_name": true, "last_name": true,
"date_of_birth": true
},
"face_match": { "status": "matched", "score": 92,
"liveness": "passed" },
"data": {
"full_name": "ADAEZE TEST OKAFOR",
"date_of_birth": "1990-01-15", …
},
"amount_charged": 150, "currency": "NGN"
}

Liveness detection

A real person, not a photo of one

A selfie can be a picture of a picture. The liveness check takes about 20 seconds in any phone browser, or inside your own iOS and Android app with our React Native and Flutter packages, and stops printed photos, screens, replayed videos and still images.

In your customer’s language

Every prompt, tip and message, in the language they choose. It starts in their phone’s language, so it’s easy for every customer to follow.

  • English
  • Pidgin
  • Hausa
  • Yorùbá
  • Igbo
  1. 1.

    Depth. The person moves closer to the camera. A real face changes shape with perspective; a photo or a screen stays flat.

  2. 2.

    Colour flash. The screen flashes colours picked for this session only. They have to reflect off the face, which a recording can’t do.

  3. 3.

    Random prompts. Two random actions, such as a blink or a head turn, each checked within its own moment.

  4. 4.

    Face match. The face that passed, not an uploaded selfie, is compared with the photo on the ID record.

  5. 5.

    Duplicate check. Optional: a face already verified under a different BVN or NIN is flagged, so one person can’t open several accounts.

₦50.00 per session, refunded if it’s never completed.

Fraud checks

Stop fraud before it becomes a customer

A real ID and a real face aren’t the whole story. These checks catch fake or altered documents, sanctioned people and companies, and one person opening several accounts.

ID documents

Read and check the ID itself

Your customer photographs their NIN slip or card, driver’s licence, voter’s card or international passport. We read it, check it, and compare its photo with the face that passed liveness.

  • Expiry, and the passport’s machine-readable check digits
  • Visible tampering: a photo of a screen, a photocopy, edited text
  • The number looked up in the registry against the name on the card
POST /documents/verify

₦100.00 per document

AML screening

Screen names against sanctions lists

Check a customer or a company against the UN, US OFAC, UK, EU and Nigeria sanctions lists, refreshed every day, then keep watching them. Built for real names, not exact spelling.

  • Allows for spelling, word order, titles and transliteration
  • Runs with any ID or CAC check: the verified person, or the company and each director
  • Monitoring re-screens a name after every list update and alerts you to a new match
  • Record “not a match” or “confirmed” with a note, audit-logged
POST /aml/screen

₦50.00 per name

Duplicate faces

Catch one face behind many accounts

Turn it on and every live face is compared with your earlier customers’ faces. A face already verified under a different BVN or NIN is flagged before you approve it.

  • Tells a returning customer from a second identity
  • Only your own customers are compared; stored as encrypted numbers, not photos
  • Turning it off deletes every stored face
Dashboard setting

₦20.00 per face

Checks and pricing

Every check returns the same shape: a status, the fields that matched, and the record. You pay per record found. Not-found lookups and registry errors are refunded automatically, and sandbox calls are free.

  • BVN₦100.00

    Name, date of birth, phone, photo

    POST /identity/bvn₦150.00 with face match
  • NIN₦100.00

    Name, date of birth, address, photo

    POST /identity/nin₦150.00 with face match
  • Driver’s licence₦150.00

    Name, date of birth, issue and expiry, photo

    POST /identity/drivers-license₦200.00 with face match
  • Voter’s card₦150.00

    Name, VIN details, photo

    POST /identity/voters-card₦200.00 with face match
  • Tax ID (TIN)₦100.00

    Registered name and status

    POST /identity/tin
  • CAC₦200.00

    Company status, address, directors, owners

    POST /business/cac
  • Liveness₦50.00

    Hosted camera check, per session

    POST /liveness/sessions
  • ID document₦100.00

    Photo of an ID read and checked, per document

    POST /documents/verify
  • AML screening₦50.00

    UN, OFAC, UK, EU and Nigeria sanctions lists, per name

    POST /aml/screen
  • AML monitoring₦20.00

    A name re-screened after every list update, per name, monthly

    POST /aml/monitors
  • Duplicate face check₦20.00

    Each live face compared with your earlier customers, per face

Prices in naira. High volume? Custom rates are available once you’re set up.

Built for developers

Two calls for a fully verified, live customer. The edge cases are handled for you.

Official libraries
Node, Python and PHP for your server, with no dependencies. They retry timeouts for you, and webhook signatures are checked in one line.
Idempotent references
Retry after a timeout with the same reference. You are never charged twice.
Errors you can branch on
Stable error codes, human-readable messages, and every invalid field listed.
A deterministic sandbox
The last two digits choose the outcome, and liveness can be simulated, so every path runs in CI.
Request IDs everywhere
Every response carries a request_id. Quote it and we can trace the call.

Sandbox to live: sign up and your sandbox key works at once. Build and test every outcome for free, then submit your CAC details for review, fund your wallet, and swap uvk_test_ for uvk_live_.

Read the API reference
node.js
import { UVerify } from '@uverifyng/node';

const uverify = new UVerify({ apiKey: process.env.UVERIFY_API_KEY });

// 1. Create a liveness session and send your customer to the link
const session = await uverify.liveness.createSession({
  redirect_url: 'https://yourapp.com/kyc/done',
});
redirect(session.url);

// 2. When they return, match the live face to their ID record
const v = await uverify.identity.bvnFaceMatch({
  id_number, first_name, last_name,
  liveness_session_id: session.id,
  aml_screening: true, // and screen them against sanctions lists
});

if (v.status === 'verified'
    && v.face_match?.status === 'matched'
    && v.aml_screening?.status === 'clear') {
  approve(customer);
}

SDKs

Your language, and inside your app

Call every check from your server with the Node, Python or PHP library. Run the face check inside your own iOS and Android app with the React Native or Flutter package: it opens our hosted check in the app and hands you the result, so every anti-spoofing layer comes with it and updates reach your app without a release.

  • Node.jsServer
    npm install @uverifyng/node
  • PythonServer
    pip install uverify
  • PHPServer
    composer require uverify/uverify-php
  • React NativeFace check in your app
    npm install @uverifyng/react-native-liveness
  • FlutterFace check in your app
    flutter pub add uverify_liveness
  • Open source under the MIT licence, with an Expo demo app. View on GitHub →

Run it with your whole team

The parts that matter once you’re live, and your compliance, engineering and finance people all need a way in.

Team roles
Invite colleagues as owner, developer or finance. Developers get keys and webhooks, finance gets the wallet and statements, and nobody sees more than they need.
Two-step sign-in
Protect every dashboard login with an authenticator app, with one-time recovery codes for a lost phone.
Locked-down API keys
Limit each key to the checks it needs, to your server IPs, and to its own requests-per-minute.
Signed webhooks
Get verification, liveness and link results pushed to your server, signed so you know they came from us, and retried if you’re down.
Low-balance alerts
An email to owners and finance before the wallet runs dry, at a threshold you choose, so live checks never stop.
Statements, invoices and exports
A monthly statement on the 1st and CSV exports for your books. Approved businesses can check now and pay a monthly invoice instead of topping up first.
Your brand on every page
Your logo and colour on the liveness and verification pages your customers see, so the check feels like part of your product.
You choose how long data is kept
Set how long identity records, document data, screened names and stored faces are kept. After that they’re deleted automatically; results, charges and the audit trail stay.
A public status page
Every service checked around the clock, with its uptime on a page anyone can open, so you know before your customers do.

Encrypted at rest

Identity records sealed with AES-256-GCM.

Minimal retention

ID numbers masked and hashed. ID photos never stored. You set how long the rest is kept.

Audited access

Every view of identity data is logged: who, when and from where.

Fair billing

Charged only for records found. Everything else is refunded automatically.

Questions, answered

When am I charged?+

Only when a record is found. Not-found lookups, registry outages and face matches that couldn’t run are refunded to your wallet automatically, and every refund appears in your wallet history. A liveness session is refunded if the person never completes it.

Is there a sandbox?+

Yes. Every account gets a free sandbox key at sign-up. The last two digits of the ID number choose the outcome (found, not found, registry error, face mismatch), and liveness sessions can be completed with a single simulate call, so you can test every path in CI.

How does liveness work?+

Create a session with one API call and send your customer to the link it returns. In any phone browser they move closer to the camera, watch a few screen colours and follow two quick prompts, in about 20 seconds. The check speaks English, Nigerian Pidgin, Hausa, Yorùbá and Igbo, and starts in the phone’s own language. Then pass the session to a face-match check and the response says liveness: "passed".

What does liveness stop?+

Printed photos, photos or videos shown on another screen, pre-recorded videos and still images. It runs in the browser and isn’t certified to ISO/IEC 30107-3, so for very high-risk onboarding combine it with your other checks.

Can I verify customers without an integration?+

Yes. Create a verification link in the dashboard and send it to your customer. They enter their ID number and do the face check on a page we host, and the result appears in your dashboard. It works in sandbox too, so you can try it first.

Can you read ID documents?+

Yes. Send a photo of a NIN slip or card, driver’s licence, voter’s card or international passport to POST /documents/verify, or ask for one in a verification link. It’s read, checked for expiry and visible tampering, its number is looked up in the registry, and its photo can be matched to the customer’s live face. Photos aren’t stored, and an unreadable photo is refunded.

Which sanctions lists do you screen?+

The UN Security Council Consolidated List, the US OFAC SDN list, the UK Sanctions List, the EU Consolidated Financial Sanctions List and the Nigeria Sanctions List, each refreshed daily. A potential match is a lead for your team to review, not a verdict. Screening doesn’t yet cover politically exposed persons (PEPs) or adverse media.

Do you have SDKs?+

Yes, all open source: @uverifyng/node for Node.js, uverify for Python and uverify/uverify-php for PHP, to call every check from your server, plus @uverifyng/react-native-liveness and uverify_liveness for Flutter to run the face check inside your own app. Your API key stays on your server; the app only opens the session link.

Can I keep screening customers after onboarding?+

Yes. Turn on monitoring for a name and it’s re-screened after every daily list update. If a new potential match appears, you get an aml.match_found webhook and an email, and it’s billed monthly per name. You can also screen automatically with every verification by adding aml_screening: true.

How do I go live?+

Verify your email, submit your CAC number and documents from the dashboard, and our team reviews them, usually within one business day. Then create a live key and fund your wallet. Your code stays the same.

How is identity data protected?+

Records are encrypted at rest with AES-256-GCM, ID numbers are stored masked and hashed, ID photos are never stored, liveness captures are encrypted and removed once used, and every view of identity data in the dashboard is audit-logged.

Make your first verification in minutes

Sign up, copy your sandbox key, send one request.

Get API keys