Pengguna mengetik nomor ID nasional mereka. Didit memeriksanya terhadap database pemerintah yang mengeluarkannya di 36 negara, dan mencocokkan selfie mereka dengan foto registri jika registri mengembalikannya.
SingaporeSingapore credit bureau and utility records$4.30Tersedia
South AfricaDepartment of Home Affairs$2.20Tersedia
SwedenSkatteverket population register$0.35Tersedia
ThailandDOPA civil registration$0.35Tersedia
United KingdomUK credit bureau and financial services records$1.85Tersedia
United StatesUS credit bureau and financial services records$0.27Tersedia
UruguayDirección Nacional del Registro de Estado Civil$0.20Tersedia
VenezuelaCNE$0.20Tersedia
Ketersediaan dan tarif berasal dari katalog metode produksi, bukan dari halaman ini. Sebuah negara akan menyala di sini saat dapat diaktifkan dalam workflow Anda; tarif adalah USD per percobaan yang dijawab.
Tersedia hari ini
Tiga puluh enam registri siap hari ini. Setiap tarif dipublikasikan.
Dari Argentina hingga Afrika Selatan, setiap negara dalam katalog sudah tersedia dengan tarif per negara di sampingnya. Argentina, Nigeria, Panama, dan Afrika Selatan mengembalikan foto registri, jadi keempat negara tersebut juga menjalankan selfie, passive liveness, dan pencocokan wajah dalam satu kali lookup yang sama.
Cara kerjanya
Dari nomor ID menjadi pengguna terverifikasi dalam empat langkah.
Langkah 01 / 04
01
Buat workflow
Aktifkan lookup untuk negara-negara yang mendukungnya. Pilih apa yang terjadi pada partial match, no match, dan ketika registri tidak merespons. Atur berapa kali pengguna dapat mencoba. Tidak perlu coding.
Integrasikan
Integrasikan secara native dengan Web, iOS, Android, React Native, atau Flutter SDK kami. Redirect ke halaman yang di-host. Atau cukup kirimkan tautan kepada pengguna Anda — melalui email, SMS, WhatsApp, di mana saja.
Pengguna melalui alur
Didit meminta nomor ID dan beberapa detail dalam bahasa yang mudah dimengerti, serta memeriksa format sebelum data meninggalkan perangkat. Jika registri mengembalikan foto, kami mengambil selfie, menjalankan passive liveness, dan mencocokkan keduanya.
Anda menerima hasilnya
Webhook yang ditandatangani secara real-time menjaga database Anda tetap sinkron saat pengguna disetujui, ditolak, atau dikirim untuk ditinjau. Lakukan polling API sesuai permintaan. Atau buka konsol dan baca setiap field yang dibandingkan oleh registri.
Dibuat untuk developer · Dibuat untuk melawan penipuan · Desain terbuka
Enam kemampuan. Satu metode dalam Verifikasi ID.
Non-document lookup bukanlah produk terpisah. Ini adalah salah satu metode yang Anda aktifkan per negara, di samping document capture dan digital ID wallets, pada kontrak hasil yang sama.
Tanyakan pada registri yang mengeluarkan nomor tersebut.
Tiga puluh enam negara merespons hari ini, masing-masing melalui badan pemerintah yang mengeluarkan nomor tersebut: RENAPER di Argentina, RENIEC di Peru, NIMC dan NIBSS di Nigeria, Department of Home Affairs di Afrika Selatan. Workflow Anda membaca katalog yang sama dengan halaman ini, jadi negara baru akan muncul pada hari siap.
Cakupan pencarian
Langsung dari katalog metode
36
Registri aktif
4
Mengembalikan foto
0
Foto dokumen diperlukan
Argentina
Bolivia
Brazil
Cambodia
Canada
Chile
China
Colombia
Costa Rica
Denmark
Dominican Republic
Ecuador
El Salvador
Finland
France
Guatemala
Honduras
India
Indonesia
Kenya
Malaysia
Mexico
Netherlands
Nigeria
Norway
Panama
Paraguay
Peru
Singapore
South Africa
Sweden
Thailand
United Kingdom
United States
Uruguay
Venezuela
Setiap negara yang terdaftar sudah aktif di produksi. Entri dengan garis putus-putus, jika ada, berarti ada di katalog tapi belum diaktifkan.
02 · Apa yang diketik pengguna
Nomor ID dan dua nama. Tanpa kamera.
Setiap negara meminta field yang persis dibutuhkan oleh registrinya, dalam bahasa yang mudah dimengerti. Pemeriksaan format berjalan di perangkat, jadi nomor yang salah ketik tidak akan pernah mencapai registri dan tidak akan membebani biaya apa pun.
Apa yang diketik pengguna
Department of Home Affairs
Nomor ID 13 digit
8001015009087Tercentang
Nama depan
Thandi
Nama belakang
Mokoena
Pengecekan format berjalan sebelum data keluar dari perangkat. Nomor yang salah ketik tidak akan pernah mencapai registri dan tidak akan ditagih.
03 · Selfie dan pencocokan wajah
Cocokkan selfie dengan foto registri.
Jika registri mengembalikan foto, Didit mengambil selfie, menjalankan passive liveness, dan mencocokkan wajah dengan foto tersebut. Ketiganya berjalan dalam harga lookup, bukan biaya tambahan.
Selfie dan pencocokan wajah
Ketika registri mengembalikan foto
Foto registri
Selfie
Liveness pasifLulus
Pencocokan wajah98.6%
Biaya tambahanTidak ada
04 · Fallback
Tentukan apa yang terjadi ketika jawabannya tidak jelas.
Partial match, no match, dan registri yang tidak pernah menjawab adalah tiga opsi terpisah. Masing-masing dapat kembali ke document capture atau ditolak, dan masing-masing menunjukkan biaya jalur tersebut sebelum Anda menyimpannya. Pengguna mendapatkan satu kali percobaan secara default dan hingga lima kali.
Fallback ke dokumen
Satu sakelar per hasil
Pencocokan sebagianPencarian + $0.15
Tidak cocokPencarian + $0.15
Tidak ada jawaban dari registriHanya $0.15
Percobaan sebelum fallback (default / maks)1 / 5
05 · Bukti sesi
Baca setiap field yang dibandingkan oleh registri.
Sesi berisi satu baris per field dengan hasil exact, partial, atau no-match, sumber yang menjawab, kapan diperiksa, berapa kali percobaan yang dibutuhkan, dan foto registri jika ada.
Perbandingan bidang
Pada sesi
Pencocokan data
Nama lengkapTepat
Tanggal lahirTepat
Status IDValid
KewarganegaraanParsial
Label jaminan ini untuk reviewer Anda. Pengguna akhir tidak akan melihatnya, nama sumber, atau harganya.
06 · Penagihan
Bayar saat registri benar-benar menjawab.
Registri yang menjawab tagihan lookup, baik cocok maupun tidak. Pengambilan dokumen hanya ditagih jika pengguna melakukan fallback. Registri senyap dan nomor yang salah ketik tidak ditagih sama sekali.
Apa saja yang dikenakan biaya
Afrika Selatan, USD per percobaan yang dijawab
$2.20
Registri menjawab — cocok, parsial, atau tidak adaDikenakan biaya
Pengguna kembali ke pengambilan dokumenDikenakan biaya
Registri tidak pernah menjawabGratis
Nomor gagal dalam pemeriksaan formatGratis
Setiap tarif adalah harga retail publik dalam USD dan sudah termasuk selfie, liveness, dan pencocokan wajah jika registri mengembalikan foto. Pengambilan dokumen hanya dikenakan biaya jika pengguna kembali ke metode tersebut.
Integrasi
Satu panggilan keluar. Satu hasil yang ditandatangani kembali.
Buat sesi, kirim pengguna ke sana, dan verifikasi webhook yang ditandatangani saat hasilnya tiba. Metode yang benar-benar digunakan pengguna akan kembali pada hasil.
Tempel blok di bawah ini ke Claude Code, Cursor, Codex, Devin, Aider, atau Replit Agent. Isi placeholder my_stack dengan framework, bahasa, dan kasus penggunaanmu. Agen akan menyediakan Didit, mengaktifkan metode per negara, menghubungkan webhook, dan mengirimkannya.
didit-integration-prompt.md
# Didit non-document verification — integrate in 5 minutes
You are adding non-document identity verification to my_stack. The user types a
national ID number plus a few personal details, and Didit checks them against
the government database that issued the number. Every URL, header, and enum
value below is canonical — do not paraphrase or "improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Grab the API key for your application from the console.
## 2. Read the methods catalog first
Availability is server-driven per country. Never hard-code a country list.
The catalog is not a public REST endpoint. Read it one of two ways:
- Business Console (signed in): your application -> ID Verification ->
Countries tab. https://docs.didit.me/console/id-verification-methods
- Didit MCP server tool didit_workflow_get_id_verification_methods_catalog,
authenticated with the same x-api-key; pass country (ISO 3166-1 alpha-3)
to narrow it to one country. https://docs.didit.me/integration/mcp/tools
- Public mirror of the coverage table (no auth, read-only):
https://docs.didit.me/core-technology/id-verification/verification-methods#coverage
The catalog tells you, per ISO 3166-1 alpha-3 country code:
- whether id_lookup is available
- the source label and the public USD rate per answered attempt (36 countries
are live at the time of this prompt, from Argentina to South Africa)
- the exact request fields to ask the user for, with their format rules
- the response fields that come back, and which of them are optional
## 3. Create a workflow with the ID Verification (OCR) feature
POST https://verification.didit.me/v3/workflows/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
The ID Verification feature's enum value is OCR (UPPERCASE — strict enum;
there is no ID_VERIFICATION alias and the API rejects it). Non-document
lookup is its id_lookup method, configured per country under config.methods
on that same feature entry, in the same request. Keys are ISO 3166-1 alpha-3.
An omitted country, or an omitted methods key, means document only.
{
"workflow_label": "Non-document onboarding",
"features": [
{
"feature": "OCR",
"config": {
"methods": {
"ZAF": {
"document": { "enabled": true },
"id_lookup": {
"enabled": true,
"max_attempts": 1,
"skip_liveness_and_face_match": false,
"on_partial_match": "fallback_to_document",
"on_no_match": "fallback_to_document",
"on_provider_error": "fallback_to_document",
"response_fields": ["gender", "citizenship", "registry_portrait"]
}
}
}
}
}
]
}
Response: the workflow uuid — use it as workflow_id in step 4.
Rules that the API enforces:
- every fallback value is either fallback_to_document or decline
- max_attempts is an integer from 1 to 5, default 1
- skip_liveness_and_face_match is only accepted where the source returns a
portrait; elsewhere it is rejected
- response_fields lists the OPTIONAL fields you want stored. Required fields
are always stored and cannot be removed
- a country whose id_lookup the catalog does not mark available is rejected
- a country with no method enabled is rejected at publish time
## 4. Create a session
POST https://verification.didit.me/v3/session/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
-d '{ "workflow_id": "<id from step 3>", "vendor_data": "<your user id>" }'
Response: 201 with url (the hosted verification link), session_token and
session_id. Redirect the user to url, or open it in the SDK. The field is
named url — there is no session_url and no verification_url.
Didit asks the user for the request fields in plain language, runs the
client-side format check, then queries the registry.
Where the registry returns a portrait (Argentina, Nigeria, Panama, South
Africa), Didit also takes a selfie, runs passive liveness on it, and
face-matches it to that portrait. All of it is inside the lookup price.
## 5. Webhooks
Register a destination (console -> API & Webhooks, or
POST https://verification.didit.me/v3/webhook/destinations/ with
webhook_version "v3" and subscribed_events ["status.updated"]) and store the
secret_shared_key it returns. Verify every delivery:
Header: X-Signature-V2 (NOT X-Signature, NOT X-Signature-Simple)
Algorithm: HMAC-SHA256, hex digest, over the CANONICAL JSON of the payload:
parse the body, sort keys recursively, serialise compact with
Unicode preserved and whole-valued floats as integers. Do NOT
hash the raw request bytes — that is the v1 X-Signature
algorithm and fails for V2 whenever whitespace or key order
differs from the canonical form.
Freshness: the signed body field timestamp is the dispatch time (Unix
seconds, refreshed on every retry). Reject when
abs(now - timestamp) > 300 seconds, and reject when the
X-Timestamp header does not equal it. The header is not
covered by the signature, so it must never be the only replay
check: a captured delivery replays with just that header
refreshed.
Compare: constant-time (crypto.timingSafeEqual)
Reference handler (Express) — use it as written:
const crypto = require("crypto");
// X-Signature-V2 signs canonical JSON: keys sorted as strings, compact,
// Unicode preserved. Emit the sorted entries directly - rebuilding an object
// would reorder integer-like keys ("10", "2"). Never hash req.rawBody.
const canonical = (v) =>
Array.isArray(v) ? "[" + v.map(canonical).join(",") + "]"
: v && typeof v === "object"
? "{" + Object.keys(v).sort()
.map((k) => JSON.stringify(k) + ":" + canonical(v[k])).join(",") + "}"
: JSON.stringify(v);
app.post("/webhooks/didit", express.json(), (req, res) => {
// Freshness: the signed body timestamp (refreshed on retry) must be recent
// and X-Timestamp must agree - the header alone is unsigned and replayable.
const ts = Number(req.body?.timestamp);
if (!ts || String(ts) !== req.headers["x-timestamp"] ||
Math.abs(Date.now() / 1000 - ts) > 300) return res.sendStatus(401);
const expected = crypto.createHmac("sha256", SECRET)
.update(canonical(req.body), "utf8").digest("hex");
const sig = String(req.headers["x-signature-v2"] ?? "");
const valid = sig.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
if (!valid) return res.sendStatus(401);
const { status, decision } = req.body;
// One entry per ID Verification node; pick yours by node_id when you run several.
const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Body fields you will use: session_id, status, webhook_type, workflow_id,
vendor_data, decision.
Status values: Approved, Declined, In Review, In Progress, Not Started,
Abandoned.
## 6. Reading the result
The decision is the V3 shape: every feature result is a plural array with one
entry per workflow node. ID Verification results live in
decision.id_verifications[] — there is no singular decision.kyc (that is the
V2 shape) and no decision.id_verification. Select your entry by node_id (the
id of your ID Verification node in the workflow graph); with a single ID step,
take index 0. Each entry carries, next to the document fields:
verification_method "document" | "id_lookup" | "wallet"
assurance "documentary" | "data_match" | "cryptographic"
id_lookup source label, checked_at, attempts, outcome, one
comparison row per field with match / partial /
no_match, and the registry portrait reference when
there is one; null on document entries
fallback_from { method, reason, action } when the session fell
back to document capture or was declined; else null
A non-document entry that succeeds is assurance data_match, never
documentary. The fallbacks only govern unsuccessful lookups (partial match,
no match, provider error): a lookup that matches is accepted as the ID result
and never reaches them, so switching them to decline does not add documentary
evidence. If your risk policy needs documentary assurance for a segment, do
not enable id_lookup for that segment's country: configure
"document": { "enabled": true } alone (omit the id_lookup key, or set its
enabled to false) and route that segment to a workflow of its own when other
users may keep the lookup. As a final guard, treat any id_verifications[]
entry whose assurance is not documentary as failing that policy.
Field-by-field reference: https://docs.didit.me/reference/data-models#id-verification
## 7. Billing — what actually bills
- a registry that answered bills the lookup. Match, partial match and no
match all count as answered
- document capture bills on top when the user falls back
- a source that never answered is not billed
- a number that fails the client-side format check never reaches the registry
and is neither counted nor billed
## 8. Hard rules — do not change
- base URL for v3 endpoints: verification.didit.me
- auth header: x-api-key (lowercase, hyphenated)
- webhook headers: X-Signature-V2 plus X-Timestamp; canonical JSON, never
raw bytes; freshness from the signed body timestamp
- feature enum: OCR (uppercase) — the ID Verification feature; per-country
methods go under its config.methods
- method keys: document, id_lookup, wallet (lowercase, snake_case)
- country keys: ISO 3166-1 alpha-3, uppercase
- result path: decision.id_verifications[] (array), never decision.kyc
## 9. Verify your integration
- run one session per configured country in sandbox
- assert the id_verifications[] entry for your node has verification_method
id_lookup on the happy path
- force a no-match and assert the fallback you configured actually fires
- for a segment that needs documentary assurance, run a lookup that matches
against that segment's workflow and assert its entry has
verification_method document and assurance documentary
- assert your webhook accepts a correctly signed payload with reordered
keys, whitespace and integer-like metadata keys ("10" before "2"), and
rejects a wrong X-Signature-V2, a payload whose signed timestamp is older
than 300 seconds, and that same stale payload with only the X-Timestamp
header refreshed
Docs: https://docs.didit.me/integration/integration-prompt
Dirancang untuk kepatuhan
Buka negara baru dengan satu klik. Kami yang mengerjakan bagian sulitnya.
Kami membuka anak perusahaan lokal, mengamankan lisensi, menjalankan pengujian penetrasi, mendapatkan sertifikasi, dan menyelaraskan dengan setiap regulasi baru. Untuk meluncurkan verifikasi di negara baru, cukup aktifkan tombol. 220+ negara sudah aktif, diaudit dan diuji penetrasi setiap kuartal, satu-satunya penyedia identitas yang secara formal disebut oleh pemerintah negara anggota Uni Eropa lebih aman daripada verifikasi langsung.
Mengembalikan foto registri untuk pencocokan wajah
$0.05–$4.30
Per lookup yang dijawab, berdasarkan negara
$0.15
Pengambilan dokumen, saat pengguna melakukan fallback
Tiga tingkatan, satu daftar harga
Mulai gratis. Bayar sesuai pemakaian. Skalakan ke Enterprise.
500 verifikasi gratis setiap bulan, selamanya. Setelah itu, bayar hanya saat modul berjalan. Kontrak khusus, data residency, dan service level agreement (SLA) tersedia untuk Enterprise.
Gratis
$0/ bulan · tanpa kartu
Untuk membangun, menguji, dan pengguna pertamamu.
Semua yang kamu butuhkan untuk memulai:
500 verifikasi KYC lengkap setiap bulan
ID, liveness, face match, device & IP
200+ sinyal fraud, blocklist, duplikat
KYC yang bisa digunakan kembali di seluruh jaringan Didit
Workflow builder, case management, SDK
Dukungan AIAgen AI dalam konsol, dokumentasi, dan komunitas.