L'usuari introdueix el seu número d'identificació nacional. Didit el comprova amb la base de dades governamental que el va emetre en 36 països, i compara la seva selfie amb la foto del registre quan el registre la retorna.
SingaporeSingapore credit bureau and utility records$4.30Actiu
South AfricaDepartment of Home Affairs$2.20Actiu
SwedenSkatteverket population register$0.35Actiu
ThailandDOPA civil registration$0.35Actiu
United KingdomUK credit bureau and financial services records$1.85Actiu
United StatesUS credit bureau and financial services records$0.27Actiu
UruguayDirección Nacional del Registro de Estado Civil$0.20Actiu
VenezuelaCNE$0.20Actiu
La disponibilitat i les tarifes provenen del catàleg de mètodes de producció, no d'aquesta pàgina. Un país s'il·lumina aquí en el moment en què es pot activar dins del teu flux de treball; una tarifa és en USD per intent respost.
Disponible avui
Trenta-sis registres responen avui. Cada tarifa és pública.
Des de l'Argentina fins a Sud-àfrica, tots els països del catàleg estan actius amb la seva tarifa per país al costat. L'Argentina, Nigèria, Panamà i Sud-àfrica retornen una foto del registre, de manera que aquests quatre també executen un selfie, una prova de vida passiva i una coincidència facial dins de la mateixa cerca.
Com funciona
D'un número d'identificació a un usuari verificat en quatre passos.
Pas 01 / 04
01
Crea el flux de treball
Activa la cerca per als països que la suporten. Tria què passa en cas de coincidència parcial, de no coincidència i quan el registre no respon. Configura quants intents té l'usuari. No cal codi.
Integra
Integra de forma nativa amb el nostre SDK per a Web, iOS, Android, React Native o Flutter. Redirigeix a una pàgina allotjada. O simplement envia un enllaç al teu usuari —per correu electrònic, SMS, WhatsApp, on vulguis.
L'usuari segueix el flux
Didit demana el número d'identificació i alguns detalls en llenguatge senzill i comprova el format abans que res surti del dispositiu. Quan el registre retorna una foto, fem un selfie, hi apliquem una prova de vida passiva i comparem les dues.
Rep els resultats
Els webhooks signats en temps real mantenen la teva base de dades sincronitzada en el moment en què un usuari és aprovat, rebutjat o enviat a revisió. Consulta l'API sota demanda. O obre la consola i llegeix tots els camps que el registre va comparar.
Creat per a desenvolupadors · Creat contra el frau · Disseny obert
Sis capacitats. Un mètode dins de la verificació d'identitat.
La cerca sense documents no és un producte separat. És un mètode que actives per país, al costat de la captura de documents i les carteres d'identitat digital, en el mateix contracte de resultats.
Trenta-sis països responen avui, cadascun a través de l'organisme governamental que va emetre el número: RENAPER a l'Argentina, RENIEC al Perú, NIMC i NIBSS a Nigèria, el Departament d'Afers Interns a Sud-àfrica. El teu flux de treball llegeix el mateix catàleg que aquesta pàgina, de manera que un nou país apareix el dia que està llest.
Cobertura de cerca
Directament des del catàleg de mètodes
36
Registres en directe
4
Retorna una foto
0
Calen fotos de documents
Argentina
Bolivia
Brazil
Cambodia
Canada
Chile
China
Colombia
Costa Rica
Denmark
Dominican Republic
Ecuador
El Salvador
Finland
France
Guatemala
Honduras
India
Indonesia
Kenya
Malaysia
Mexico
Netherlands
Nigeria
Norway
Panama
Paraguay
Peru
Singapore
South Africa
Sweden
Thailand
United Kingdom
United States
Uruguay
Venezuela
Tots els països llistats estan en producció. Una entrada amb guions, si n'apareix alguna aquí, és al catàleg però encara no està activada.
02 · Què escriu l'usuari
Un número d'identificació i dos noms. Sense càmera.
Cada país demana exactament els camps que el seu registre necessita, en llenguatge senzill. La comprovació de format s'executa al dispositiu, de manera que un número mal escrit mai arriba al registre i mai et costa res.
Què escriu l'usuari
Department of Home Affairs
Número d'identificació de 13 dígits
8001015009087Comprovat
Nom
Thandi
Cognom
Mokoena
La comprovació de format s'executa abans que res surti del dispositiu. Un número mal escrit mai arriba al registre i mai es factura.
03 · Selfie i coincidència facial
Compara un selfie amb la foto del registre.
Quan el registre retorna un retrat, Didit fa un selfie, hi aplica una prova de vida passiva i el compara amb aquest retrat. Els tres s'executen dins del preu de la cerca, no a part.
Selfie i coincidència facial
On el registre retorna una foto
Foto del registre
Selfie
Liveness passiuSuperat
Coincidència facial98.6%
Cost addicionalCap
04 · Alternatives
Decideix què passa quan la resposta no és clara.
La coincidència parcial, la no coincidència i un registre que mai va respondre són tres interruptors separats. Cadascun torna a la captura de documents o rebutja, i cadascun mostra el cost d'aquest camí abans de desar-lo. L'usuari té un intent per defecte i fins a cinc.
Torna a un document
Un interruptor per resultat
Coincidència parcialCerca + $0.15
Sense coincidènciaCerca + $0.15
Sense resposta del registreNomés $0.15
Intents abans de tornar (per defecte / màxim)1 / 5
05 · Evidència de la sessió
Llegeix tots els camps que el registre va comparar.
La sessió conté una fila per camp amb un veredicte de coincidència exacta, parcial o nul·la, la font que va respondre, quan es va comprovar, quants intents va trigar i la foto del registre quan n'hi ha una.
Comparació de camps
A la sessió
Coincidència de dades
Nom completExacte
Data de naixementExacte
Estat de la identificacióVàlid
NacionalitatParcial
Les etiquetes de garantia són per als teus revisors. L'usuari final mai les veu, ni el nom de la font, ni el preu.
06 · Facturació
Paga quan un registre realment respon.
Es factura cada consulta al registre, tant si hi ha coincidència com si no. La captura de documents només es factura addicionalment si l'usuari ha de recórrer-hi. Una consulta silenciosa o un número mal escrit no es facturen en absolut.
Què es factura realment
Sud-àfrica, USD per intent respost
$2.20
Registre respost — coincidència, parcial o capFacturat
L'usuari va tornar a la captura de documentsFacturat
El registre no va respondre maiGratuït
El número no va superar la comprovació de formatGratuït
Totes les tarifes són preus de venda al públic en USD i inclouen el selfie, la prova de vida i la coincidència facial quan el registre retorna una foto. La captura de documents només es factura quan l'usuari torna a aquest mètode.
Integració
Una crida. Un resultat signat de tornada.
Crea la sessió, envia-hi l'usuari i verifica el webhook signat quan arribi el resultat. El mètode que l'usuari ha utilitzat realment es retorna amb el resultat.
Desplega la verificació sense documents amb una sola indicació.
Enganxa el bloc següent a Claude Code, Cursor, Codex, Devin, Aider o Replit Agent. Omple el marcador de posició `my_stack` amb el teu framework, llenguatge i cas d'ús. L'agent aprovisiona Didit, activa el mètode per país, connecta el webhook i ho desplega.
didit-integration-prompt.md
# Didit non-document verification — integrate in 5 minutes
You are adding non-document identity verification to my_stack. The user types a
national ID number plus a few personal details, and Didit checks them against
the government database that issued the number. Every URL, header, and enum
value below is canonical — do not paraphrase or "improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Grab the API key for your application from the console.
## 2. Read the methods catalog first
Availability is server-driven per country. Never hard-code a country list.
The catalog is not a public REST endpoint. Read it one of two ways:
- Business Console (signed in): your application -> ID Verification ->
Countries tab. https://docs.didit.me/console/id-verification-methods
- Didit MCP server tool didit_workflow_get_id_verification_methods_catalog,
authenticated with the same x-api-key; pass country (ISO 3166-1 alpha-3)
to narrow it to one country. https://docs.didit.me/integration/mcp/tools
- Public mirror of the coverage table (no auth, read-only):
https://docs.didit.me/core-technology/id-verification/verification-methods#coverage
The catalog tells you, per ISO 3166-1 alpha-3 country code:
- whether id_lookup is available
- the source label and the public USD rate per answered attempt (36 countries
are live at the time of this prompt, from Argentina to South Africa)
- the exact request fields to ask the user for, with their format rules
- the response fields that come back, and which of them are optional
## 3. Create a workflow with the ID Verification (OCR) feature
POST https://verification.didit.me/v3/workflows/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
The ID Verification feature's enum value is OCR (UPPERCASE — strict enum;
there is no ID_VERIFICATION alias and the API rejects it). Non-document
lookup is its id_lookup method, configured per country under config.methods
on that same feature entry, in the same request. Keys are ISO 3166-1 alpha-3.
An omitted country, or an omitted methods key, means document only.
{
"workflow_label": "Non-document onboarding",
"features": [
{
"feature": "OCR",
"config": {
"methods": {
"ZAF": {
"document": { "enabled": true },
"id_lookup": {
"enabled": true,
"max_attempts": 1,
"skip_liveness_and_face_match": false,
"on_partial_match": "fallback_to_document",
"on_no_match": "fallback_to_document",
"on_provider_error": "fallback_to_document",
"response_fields": ["gender", "citizenship", "registry_portrait"]
}
}
}
}
}
]
}
Response: the workflow uuid — use it as workflow_id in step 4.
Rules that the API enforces:
- every fallback value is either fallback_to_document or decline
- max_attempts is an integer from 1 to 5, default 1
- skip_liveness_and_face_match is only accepted where the source returns a
portrait; elsewhere it is rejected
- response_fields lists the OPTIONAL fields you want stored. Required fields
are always stored and cannot be removed
- a country whose id_lookup the catalog does not mark available is rejected
- a country with no method enabled is rejected at publish time
## 4. Create a session
POST https://verification.didit.me/v3/session/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
-d '{ "workflow_id": "<id from step 3>", "vendor_data": "<your user id>" }'
Response: 201 with url (the hosted verification link), session_token and
session_id. Redirect the user to url, or open it in the SDK. The field is
named url — there is no session_url and no verification_url.
Didit asks the user for the request fields in plain language, runs the
client-side format check, then queries the registry.
Where the registry returns a portrait (Argentina, Nigeria, Panama, South
Africa), Didit also takes a selfie, runs passive liveness on it, and
face-matches it to that portrait. All of it is inside the lookup price.
## 5. Webhooks
Register a destination (console -> API & Webhooks, or
POST https://verification.didit.me/v3/webhook/destinations/ with
webhook_version "v3" and subscribed_events ["status.updated"]) and store the
secret_shared_key it returns. Verify every delivery:
Header: X-Signature-V2 (NOT X-Signature, NOT X-Signature-Simple)
Algorithm: HMAC-SHA256, hex digest, over the CANONICAL JSON of the payload:
parse the body, sort keys recursively, serialise compact with
Unicode preserved and whole-valued floats as integers. Do NOT
hash the raw request bytes — that is the v1 X-Signature
algorithm and fails for V2 whenever whitespace or key order
differs from the canonical form.
Freshness: the signed body field timestamp is the dispatch time (Unix
seconds, refreshed on every retry). Reject when
abs(now - timestamp) > 300 seconds, and reject when the
X-Timestamp header does not equal it. The header is not
covered by the signature, so it must never be the only replay
check: a captured delivery replays with just that header
refreshed.
Compare: constant-time (crypto.timingSafeEqual)
Reference handler (Express) — use it as written:
const crypto = require("crypto");
// X-Signature-V2 signs canonical JSON: keys sorted as strings, compact,
// Unicode preserved. Emit the sorted entries directly - rebuilding an object
// would reorder integer-like keys ("10", "2"). Never hash req.rawBody.
const canonical = (v) =>
Array.isArray(v) ? "[" + v.map(canonical).join(",") + "]"
: v && typeof v === "object"
? "{" + Object.keys(v).sort()
.map((k) => JSON.stringify(k) + ":" + canonical(v[k])).join(",") + "}"
: JSON.stringify(v);
app.post("/webhooks/didit", express.json(), (req, res) => {
// Freshness: the signed body timestamp (refreshed on retry) must be recent
// and X-Timestamp must agree - the header alone is unsigned and replayable.
const ts = Number(req.body?.timestamp);
if (!ts || String(ts) !== req.headers["x-timestamp"] ||
Math.abs(Date.now() / 1000 - ts) > 300) return res.sendStatus(401);
const expected = crypto.createHmac("sha256", SECRET)
.update(canonical(req.body), "utf8").digest("hex");
const sig = String(req.headers["x-signature-v2"] ?? "");
const valid = sig.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
if (!valid) return res.sendStatus(401);
const { status, decision } = req.body;
// One entry per ID Verification node; pick yours by node_id when you run several.
const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Body fields you will use: session_id, status, webhook_type, workflow_id,
vendor_data, decision.
Status values: Approved, Declined, In Review, In Progress, Not Started,
Abandoned.
## 6. Reading the result
The decision is the V3 shape: every feature result is a plural array with one
entry per workflow node. ID Verification results live in
decision.id_verifications[] — there is no singular decision.kyc (that is the
V2 shape) and no decision.id_verification. Select your entry by node_id (the
id of your ID Verification node in the workflow graph); with a single ID step,
take index 0. Each entry carries, next to the document fields:
verification_method "document" | "id_lookup" | "wallet"
assurance "documentary" | "data_match" | "cryptographic"
id_lookup source label, checked_at, attempts, outcome, one
comparison row per field with match / partial /
no_match, and the registry portrait reference when
there is one; null on document entries
fallback_from { method, reason, action } when the session fell
back to document capture or was declined; else null
A non-document entry that succeeds is assurance data_match, never
documentary. The fallbacks only govern unsuccessful lookups (partial match,
no match, provider error): a lookup that matches is accepted as the ID result
and never reaches them, so switching them to decline does not add documentary
evidence. If your risk policy needs documentary assurance for a segment, do
not enable id_lookup for that segment's country: configure
"document": { "enabled": true } alone (omit the id_lookup key, or set its
enabled to false) and route that segment to a workflow of its own when other
users may keep the lookup. As a final guard, treat any id_verifications[]
entry whose assurance is not documentary as failing that policy.
Field-by-field reference: https://docs.didit.me/reference/data-models#id-verification
## 7. Billing — what actually bills
- a registry that answered bills the lookup. Match, partial match and no
match all count as answered
- document capture bills on top when the user falls back
- a source that never answered is not billed
- a number that fails the client-side format check never reaches the registry
and is neither counted nor billed
## 8. Hard rules — do not change
- base URL for v3 endpoints: verification.didit.me
- auth header: x-api-key (lowercase, hyphenated)
- webhook headers: X-Signature-V2 plus X-Timestamp; canonical JSON, never
raw bytes; freshness from the signed body timestamp
- feature enum: OCR (uppercase) — the ID Verification feature; per-country
methods go under its config.methods
- method keys: document, id_lookup, wallet (lowercase, snake_case)
- country keys: ISO 3166-1 alpha-3, uppercase
- result path: decision.id_verifications[] (array), never decision.kyc
## 9. Verify your integration
- run one session per configured country in sandbox
- assert the id_verifications[] entry for your node has verification_method
id_lookup on the happy path
- force a no-match and assert the fallback you configured actually fires
- for a segment that needs documentary assurance, run a lookup that matches
against that segment's workflow and assert its entry has
verification_method document and assurance documentary
- assert your webhook accepts a correctly signed payload with reordered
keys, whitespace and integer-like metadata keys ("10" before "2"), and
rejects a wrong X-Signature-V2, a payload whose signed timestamp is older
than 300 seconds, and that same stale payload with only the X-Timestamp
header refreshed
Docs: https://docs.didit.me/integration/integration-prompt
Compliment per disseny
Obre un nou país amb un clic. Nosaltres fem la feina difícil.
Obrim les filials locals, assegurem les llicències, realitzem les proves de penetració, obtenim les certificacions i ens alineem amb cada nova regulació. Per desplegar verificacions en un nou país, només has d'activar un interruptor. Més de 220 països en funcionament, auditats i provats trimestralment, l'únic proveïdor d'identitat que un govern d'un estat membre de la UE ha qualificat formalment com més segur que la verificació presencial.
Retorna una foto de registre per a la coincidència facial
$0.05–$4.30
Per consulta resposta, per país
$0.15
Captura de documents, quan un usuari ha de recórrer-hi
Tres nivells, una llista de preus
Comença gratis. Paga per ús. Escala a Enterprise.
500 verificacions gratuïtes cada mes, per sempre. Després, paga només quan s'executa un mòdul. Contractes personalitzats, residència de dades i acords de nivell de servei (SLA) a Enterprise.
Gratuït
$0/ mes · sense targeta
Per construir, provar i per als teus primers usuaris.
Tot el que necessites per començar:
500 verificacions KYC completes cada mes
Identificació, prova de vida, coincidència facial, dispositiu i IP
Més de 200 senyals de frau, llista de bloqueig, duplicats
KYC reutilitzable a tota la xarxa Didit
Constructor de fluxos de treball, gestió de casos, SDKs
Suport amb IAAgent d'IA a la consola, documentació i comunitat.