El usuario introduce su número de identificación nacional. Didit lo coteja con la base de datos gubernamental que lo emitió en 36 países, y compara su selfie con la foto del registro cuando este la devuelve.
SingaporeSingapore credit bureau and utility records$4.30Disponible
South AfricaDepartment of Home Affairs$2.20Disponible
SwedenSkatteverket population register$0.35Disponible
ThailandDOPA civil registration$0.35Disponible
United KingdomUK credit bureau and financial services records$1.85Disponible
United StatesUS credit bureau and financial services records$0.27Disponible
UruguayDirección Nacional del Registro de Estado Civil$0.20Disponible
VenezuelaCNE$0.20Disponible
La disponibilidad y las tarifas provienen del catálogo de métodos de producción, no de esta página. Un país se ilumina aquí en el momento en que se puede activar dentro de tu flujo de trabajo; una tarifa es en USD por intento respondido.
Disponible hoy
Treinta y seis registros responden hoy. Todas las tarifas están publicadas.
Desde Argentina hasta Sudáfrica, todos los países del catálogo están disponibles con su tarifa por país al lado. Argentina, Nigeria, Panamá y Sudáfrica devuelven una foto del registro, por lo que esos cuatro también ejecutan una selfie, detección de vida pasiva y una coincidencia facial dentro de la misma búsqueda.
Cómo funciona
De un número de identificación a un usuario verificado en cuatro pasos.
Paso 01 / 04
01
Crea el flujo de trabajo
Activa la búsqueda para los países que la admiten. Elige qué sucede en caso de coincidencia parcial, sin coincidencia y cuando el registro permanece en silencio. Establece cuántos intentos tiene el usuario. No se requiere código.
Integra
Integra de forma nativa con nuestro SDK para Web, iOS, Android, React Native o Flutter. Redirige a una página alojada. O simplemente envía a tu usuario un enlace, por correo electrónico, SMS, WhatsApp, donde quieras.
El usuario completa el flujo
Didit solicita el número de identificación y algunos detalles en lenguaje sencillo, y verifica el formato antes de que nada salga del dispositivo. Cuando el registro devuelve una foto, tomamos una selfie, ejecutamos la detección de vida pasiva y las comparamos.
Recibes los resultados
Los webhooks firmados en tiempo real mantienen tu base de datos sincronizada en el momento en que un usuario es aprobado, rechazado o enviado a revisión. Consulta la API bajo demanda. O abre la consola y lee cada campo que el registro comparó.
Diseñado para desarrolladores · Diseñado contra el fraude · Abierto por diseño
Seis capacidades. Un método dentro de la Verificación de Identidad.
La verificación sin documentos no es un producto separado. Es un método que activas por país, junto con la captura de documentos y las carteras de identidad digital, en el mismo contrato de resultados.
Treinta y seis países responden hoy, cada uno a través del organismo gubernamental que emitió el número: RENAPER en Argentina, RENIEC en Perú, NIMC y NIBSS en Nigeria, el Departamento del Interior en Sudáfrica. Tu flujo de trabajo lee el mismo catálogo que esta página, por lo que un nuevo país aparece el día que está listo.
Cobertura de búsqueda
Directo del catálogo de métodos
36
Registros activos
4
Devolver una foto
0
Fotos de documentos necesarias
Argentina
Bolivia
Brazil
Cambodia
Canada
Chile
China
Colombia
Costa Rica
Denmark
Dominican Republic
Ecuador
El Salvador
Finland
France
Guatemala
Honduras
India
Indonesia
Kenya
Malaysia
Mexico
Netherlands
Nigeria
Norway
Panama
Paraguay
Peru
Singapore
South Africa
Sweden
Thailand
United Kingdom
United States
Uruguay
Venezuela
Cada país listado está activo en producción. Una entrada con guiones, si aparece aquí, está en el catálogo pero aún no está activada.
02 · Lo que el usuario escribe
Un número de identificación y dos nombres. Sin cámara.
Cada país solicita exactamente los campos que su registro necesita, en lenguaje sencillo. La verificación de formato se ejecuta en el dispositivo, por lo que un número mal escrito nunca llega al registro y nunca te cuesta nada.
Lo que el usuario escribe
Department of Home Affairs
Número de identificación de 13 dígitos
8001015009087Verificado
Nombre
Thandi
Apellido
Mokoena
La verificación de formato se ejecuta antes de que nada salga del dispositivo. Un número mal escrito nunca llega al registro y nunca se factura.
03 · Selfie y coincidencia facial
Compara una selfie con la foto del registro.
Cuando el registro devuelve un retrato, Didit toma una selfie, ejecuta la detección de vida pasiva y la compara con ese retrato. Los tres se ejecutan dentro del precio de la búsqueda, no como un coste adicional.
Selfie y coincidencia facial
Cuando el registro devuelve una foto
Foto del registro
Selfie
Prueba de vida pasivaAprobado
Coincidencia facial98.6%
Coste adicionalNinguno
04 · Alternativas
Decide qué sucede cuando la respuesta no es clara.
Coincidencia parcial, sin coincidencia y un registro que nunca respondió son tres opciones separadas. Cada una recurre a la captura de documentos o rechaza, y cada una muestra lo que cuesta ese camino antes de que lo guardes. El usuario tiene un intento por defecto y hasta cinco.
Volver a un documento
Un interruptor por resultado
Coincidencia parcialBúsqueda + $0.15
Sin coincidenciaBúsqueda + $0.15
Sin respuesta del registroSolo $0.15
Intentos antes de recurrir (predeterminado / máximo)1 / 5
05 · Evidencia de sesión
Lee cada campo que el registro comparó.
La sesión contiene una fila por campo con un veredicto de coincidencia exacta, parcial o sin coincidencia, la fuente que respondió, cuándo se verificó, cuántos intentos tomó y la foto del registro cuando la hay.
Comparación de campos
En la sesión
Coincidencia de datos
Nombre completoExacto
Fecha de nacimientoExacto
Estado del IDVálido
NacionalidadParcial
Las etiquetas de garantía son para tus revisores. El usuario final nunca las ve, ni el nombre de la fuente, ni el precio.
06 · Facturación
Paga cuando un registro realmente responde.
Se factura cada consulta al registro, haya coincidido o no. La captura de documentos solo se factura si el usuario recurre a ella. Un registro silencioso o un número mal escrito no generan ningún coste.
Qué se factura realmente
Sudáfrica, USD por intento respondido
$2.20
Registro respondido: coincidencia, parcial o ningunaFacturado
El usuario recurrió a la captura de documentosFacturado
El registro nunca respondióGratis
El número no pasó la verificación de formatoGratis
Todas las tarifas son precios minoristas públicos en USD e incluyen la selfie, la prueba de vida y la coincidencia facial cuando el registro devuelve una foto. La captura de documentos solo se factura si el usuario recurre a ella.
Integración
Una llamada. Un resultado firmado.
Crea la sesión, envía al usuario y verifica el webhook firmado cuando llegue el resultado. El método que el usuario utilizó realmente se devuelve en el resultado.
Lanza la verificación sin documentos con un solo prompt.
Pega el siguiente bloque en Claude Code, Cursor, Codex, Devin, Aider o Replit Agent. Rellena el placeholder `my_stack` con tu framework, lenguaje y caso de uso. El agente provisiona Didit, activa el método por país, configura el webhook y lo lanza.
didit-integration-prompt.md
# Didit non-document verification — integrate in 5 minutes
You are adding non-document identity verification to my_stack. The user types a
national ID number plus a few personal details, and Didit checks them against
the government database that issued the number. Every URL, header, and enum
value below is canonical — do not paraphrase or "improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Grab the API key for your application from the console.
## 2. Read the methods catalog first
Availability is server-driven per country. Never hard-code a country list.
The catalog is not a public REST endpoint. Read it one of two ways:
- Business Console (signed in): your application -> ID Verification ->
Countries tab. https://docs.didit.me/console/id-verification-methods
- Didit MCP server tool didit_workflow_get_id_verification_methods_catalog,
authenticated with the same x-api-key; pass country (ISO 3166-1 alpha-3)
to narrow it to one country. https://docs.didit.me/integration/mcp/tools
- Public mirror of the coverage table (no auth, read-only):
https://docs.didit.me/core-technology/id-verification/verification-methods#coverage
The catalog tells you, per ISO 3166-1 alpha-3 country code:
- whether id_lookup is available
- the source label and the public USD rate per answered attempt (36 countries
are live at the time of this prompt, from Argentina to South Africa)
- the exact request fields to ask the user for, with their format rules
- the response fields that come back, and which of them are optional
## 3. Create a workflow with the ID Verification (OCR) feature
POST https://verification.didit.me/v3/workflows/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
The ID Verification feature's enum value is OCR (UPPERCASE — strict enum;
there is no ID_VERIFICATION alias and the API rejects it). Non-document
lookup is its id_lookup method, configured per country under config.methods
on that same feature entry, in the same request. Keys are ISO 3166-1 alpha-3.
An omitted country, or an omitted methods key, means document only.
{
"workflow_label": "Non-document onboarding",
"features": [
{
"feature": "OCR",
"config": {
"methods": {
"ZAF": {
"document": { "enabled": true },
"id_lookup": {
"enabled": true,
"max_attempts": 1,
"skip_liveness_and_face_match": false,
"on_partial_match": "fallback_to_document",
"on_no_match": "fallback_to_document",
"on_provider_error": "fallback_to_document",
"response_fields": ["gender", "citizenship", "registry_portrait"]
}
}
}
}
}
]
}
Response: the workflow uuid — use it as workflow_id in step 4.
Rules that the API enforces:
- every fallback value is either fallback_to_document or decline
- max_attempts is an integer from 1 to 5, default 1
- skip_liveness_and_face_match is only accepted where the source returns a
portrait; elsewhere it is rejected
- response_fields lists the OPTIONAL fields you want stored. Required fields
are always stored and cannot be removed
- a country whose id_lookup the catalog does not mark available is rejected
- a country with no method enabled is rejected at publish time
## 4. Create a session
POST https://verification.didit.me/v3/session/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
-d '{ "workflow_id": "<id from step 3>", "vendor_data": "<your user id>" }'
Response: 201 with url (the hosted verification link), session_token and
session_id. Redirect the user to url, or open it in the SDK. The field is
named url — there is no session_url and no verification_url.
Didit asks the user for the request fields in plain language, runs the
client-side format check, then queries the registry.
Where the registry returns a portrait (Argentina, Nigeria, Panama, South
Africa), Didit also takes a selfie, runs passive liveness on it, and
face-matches it to that portrait. All of it is inside the lookup price.
## 5. Webhooks
Register a destination (console -> API & Webhooks, or
POST https://verification.didit.me/v3/webhook/destinations/ with
webhook_version "v3" and subscribed_events ["status.updated"]) and store the
secret_shared_key it returns. Verify every delivery:
Header: X-Signature-V2 (NOT X-Signature, NOT X-Signature-Simple)
Algorithm: HMAC-SHA256, hex digest, over the CANONICAL JSON of the payload:
parse the body, sort keys recursively, serialise compact with
Unicode preserved and whole-valued floats as integers. Do NOT
hash the raw request bytes — that is the v1 X-Signature
algorithm and fails for V2 whenever whitespace or key order
differs from the canonical form.
Freshness: the signed body field timestamp is the dispatch time (Unix
seconds, refreshed on every retry). Reject when
abs(now - timestamp) > 300 seconds, and reject when the
X-Timestamp header does not equal it. The header is not
covered by the signature, so it must never be the only replay
check: a captured delivery replays with just that header
refreshed.
Compare: constant-time (crypto.timingSafeEqual)
Reference handler (Express) — use it as written:
const crypto = require("crypto");
// X-Signature-V2 signs canonical JSON: keys sorted as strings, compact,
// Unicode preserved. Emit the sorted entries directly - rebuilding an object
// would reorder integer-like keys ("10", "2"). Never hash req.rawBody.
const canonical = (v) =>
Array.isArray(v) ? "[" + v.map(canonical).join(",") + "]"
: v && typeof v === "object"
? "{" + Object.keys(v).sort()
.map((k) => JSON.stringify(k) + ":" + canonical(v[k])).join(",") + "}"
: JSON.stringify(v);
app.post("/webhooks/didit", express.json(), (req, res) => {
// Freshness: the signed body timestamp (refreshed on retry) must be recent
// and X-Timestamp must agree - the header alone is unsigned and replayable.
const ts = Number(req.body?.timestamp);
if (!ts || String(ts) !== req.headers["x-timestamp"] ||
Math.abs(Date.now() / 1000 - ts) > 300) return res.sendStatus(401);
const expected = crypto.createHmac("sha256", SECRET)
.update(canonical(req.body), "utf8").digest("hex");
const sig = String(req.headers["x-signature-v2"] ?? "");
const valid = sig.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
if (!valid) return res.sendStatus(401);
const { status, decision } = req.body;
// One entry per ID Verification node; pick yours by node_id when you run several.
const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Body fields you will use: session_id, status, webhook_type, workflow_id,
vendor_data, decision.
Status values: Approved, Declined, In Review, In Progress, Not Started,
Abandoned.
## 6. Reading the result
The decision is the V3 shape: every feature result is a plural array with one
entry per workflow node. ID Verification results live in
decision.id_verifications[] — there is no singular decision.kyc (that is the
V2 shape) and no decision.id_verification. Select your entry by node_id (the
id of your ID Verification node in the workflow graph); with a single ID step,
take index 0. Each entry carries, next to the document fields:
verification_method "document" | "id_lookup" | "wallet"
assurance "documentary" | "data_match" | "cryptographic"
id_lookup source label, checked_at, attempts, outcome, one
comparison row per field with match / partial /
no_match, and the registry portrait reference when
there is one; null on document entries
fallback_from { method, reason, action } when the session fell
back to document capture or was declined; else null
A non-document entry that succeeds is assurance data_match, never
documentary. The fallbacks only govern unsuccessful lookups (partial match,
no match, provider error): a lookup that matches is accepted as the ID result
and never reaches them, so switching them to decline does not add documentary
evidence. If your risk policy needs documentary assurance for a segment, do
not enable id_lookup for that segment's country: configure
"document": { "enabled": true } alone (omit the id_lookup key, or set its
enabled to false) and route that segment to a workflow of its own when other
users may keep the lookup. As a final guard, treat any id_verifications[]
entry whose assurance is not documentary as failing that policy.
Field-by-field reference: https://docs.didit.me/reference/data-models#id-verification
## 7. Billing — what actually bills
- a registry that answered bills the lookup. Match, partial match and no
match all count as answered
- document capture bills on top when the user falls back
- a source that never answered is not billed
- a number that fails the client-side format check never reaches the registry
and is neither counted nor billed
## 8. Hard rules — do not change
- base URL for v3 endpoints: verification.didit.me
- auth header: x-api-key (lowercase, hyphenated)
- webhook headers: X-Signature-V2 plus X-Timestamp; canonical JSON, never
raw bytes; freshness from the signed body timestamp
- feature enum: OCR (uppercase) — the ID Verification feature; per-country
methods go under its config.methods
- method keys: document, id_lookup, wallet (lowercase, snake_case)
- country keys: ISO 3166-1 alpha-3, uppercase
- result path: decision.id_verifications[] (array), never decision.kyc
## 9. Verify your integration
- run one session per configured country in sandbox
- assert the id_verifications[] entry for your node has verification_method
id_lookup on the happy path
- force a no-match and assert the fallback you configured actually fires
- for a segment that needs documentary assurance, run a lookup that matches
against that segment's workflow and assert its entry has
verification_method document and assurance documentary
- assert your webhook accepts a correctly signed payload with reordered
keys, whitespace and integer-like metadata keys ("10" before "2"), and
rejects a wrong X-Signature-V2, a payload whose signed timestamp is older
than 300 seconds, and that same stale payload with only the X-Timestamp
header refreshed
Docs: https://docs.didit.me/integration/integration-prompt
Cumplimiento por diseño
Abre un nuevo país en un clic. Nosotros hacemos el trabajo duro.
Abrimos las filiales locales, aseguramos las licencias, realizamos las pruebas de penetración, obtenemos las certificaciones y nos alineamos con cada nueva regulación. Para lanzar verificaciones en un nuevo país, activa un interruptor. Más de 220 países en vivo, auditados y probados trimestralmente, el único proveedor de identidad que un gobierno de un estado miembro de la UE ha calificado formalmente como más seguro que la verificación presencial.
Devuelve una foto del registro para la coincidencia facial
$0.05–$4.30
Por consulta respondida, por país
$0.15
Captura de documentos, cuando un usuario recurre a ella
Tres niveles, una lista de precios
Empieza gratis. Paga por uso. Escala a Enterprise.
500 verificaciones gratis cada mes, para siempre. Después, paga solo cuando se ejecute un módulo. Contratos personalizados, residencia de datos y acuerdos de nivel de servicio (SLA) en Enterprise.
Gratis
$0/ mes · sin tarjeta
Para construir, probar y tus primeros usuarios.
Todo lo que necesitas para empezar:
500 verificaciones KYC completas cada mes
ID, prueba de vida, coincidencia facial, dispositivo e IP
Más de 200 señales de fraude, lista de bloqueo, duplicados
KYC reutilizable en toda la red Didit
Constructor de flujos de trabajo, gestión de casos, SDKs
Soporte con IAAgente de IA en consola, documentación y comunidad.