無料
月額$0。クレジットカード不要。
- 無料KYCバンドル(本人確認 + パッシブ・ライブネス + 顔照合 + デバイス&IP分析), 毎月500回まで
- ブロックリストユーザー
- 重複検出
- すべてのセッションで200以上の不正シグナル
- Diditネットワーク全体でのKYC再利用
- ケース管理プラットフォーム
- ワークフロービルダー
- 公開ドキュメント、サンドボックス、SDK、MCP (Model Context Protocol) サーバー
- コミュニティサポート
世界中の2,000以上の組織から信頼されています。

あなたのブランド、私たちの判定
フローをあなたのドメインでホスト。ロゴ、色、コピー、リンク プレビューカードを自由に設定できます。モジュール料金はそのまま、追加料金は1セッションあたり$0.20のみです。
ID、生体認証、顔照合、制裁リスト、住所、年齢、電話番号、メールアドレス、カスタム質問など、必要なチェックを選択します。ダッシュボードでドラッグ&ドロップしてフローを作成するか、API経由で同じフローを投稿します。条件分岐やA/Bテストもコード不要で実行できます。
# コンソール -> ホワイトラベル -> スタイルエディター
colors: ブランドパレット
logos: 正方形 + 長方形
typography: ブランドフォント + ウェイト
domain: verify.acme.com
email_from: verify@acme.com
# ワークフロー -> 設定 -> オプション
include_custom_style: trueあなたのブランド · `verify.acme.com` · TLS自動$ curl -X POST https://verification.didit.me/v3/session/ \
-H "x-api-key: $DIDIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"workflow_id": "wf_acme_kyc",
"vendor_data": "user-42"
}'{ "session_url": "verify.acme.com/..." }# Didit White Label — integrate in 5 minutes
You are integrating Didit's White Label (custom branding + custom domain)
into <my_stack>. White Label is a CONFIGURATION on top of any workflow —
not a separate API endpoint. Follow these steps exactly. Every URL,
header, and field below is canonical — do not paraphrase or "improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Or provision programmatically: POST https://apx.didit.me/auth/v2/programmatic/register/
(returns an API key bound to the workspace + application).
## 2. Configure White Label in the console
White Label settings live at Console -> White Label -> Style Editor. Five
groups, every one is customizable:
- Colors — buttons, text, panels, backgrounds (every color element)
- Typography — upload a brand font, set heading + body weights
- Logos — square + rectangular variants, served on every screen
- Layout — border radius for panels, buttons, inputs
- Login screen — show or skip the user-login step entirely
- Custom domain — host the verification UI on your own subdomain
(e.g. verify.acme.com) instead of verify.didit.me
Custom-domain setup:
1. Console -> White Label -> Custom Domain -> Add domain
2. We return a CNAME target. Point your subdomain CNAME at it.
3. Click Verify. We provision a TLS certificate via Let's Encrypt /
ACME (automatic renewal, no action required from you).
4. Domain becomes live within minutes.
Custom email-from:
- Console -> White Label -> Email -> set the "From" name + reply-to address.
- DKIM / SPF records returned for you to add to DNS.
## 3. Enable White Label on each workflow
The customization does NOT auto-apply. You enable it per workflow:
1. Console -> Workflows -> open the workflow you want to brand.
2. Click Settings (gear icon).
3. Under Options, find "Include custom style".
4. Enable the toggle. Save.
Workflows without the toggle keep the default Didit branding — useful for
sandbox flows you do not want to brand yet.
## 4. Use the white-labeled workflow from your stack
Once the workflow has white-label enabled, you call it the same way as any
other Didit workflow:
POST https://verification.didit.me/v3/session/
Authorization header: x-api-key: <your-api-key>
Body:
- workflow_id (required, your white-labeled workflow id)
- vendor_data (optional, your own user id)
- callback (optional, URL we redirect to after the flow)
Response: { session_url } — redirect the user there. The UI they see is
your brand (your logo, your colors, your typography), on your domain
(verify.acme.com), with your "From" name on every email we send to the
user mid-flow.
## 5. Webhooks
- Register a webhook destination once via
POST https://verification.didit.me/v3/webhook/destinations/
Body: url, subscribed_events: ["session.verified", "session.review_started",
"session.declined", "session.kyc_expired"]
- Response includes secret_shared_key — store it.
- Every webhook delivery carries an X-Signature-V2 header you MUST verify
before trusting the payload. HMAC-SHA256 verification MUST run against the raw body bytes (the raw payload as Didit sent it) BEFORE any JSON parsing — re-serialising the parsed body changes whitespace and key order, which invalidates the signature.Algorithm:
1. sortKeys(payload) recursively
2. shortenFloats (truncate trailing zeros after the decimal point)
3. JSON.stringify the result
4. HMAC-SHA256 with the secret_shared_key
5. Hex-encode, compare to the X-Signature-V2 header.
## 6. Hard rules - do not change
- Base URL for /v3/* endpoints is verification.didit.me (NOT apx.didit.me).
- Auth header is x-api-key (lowercase, hyphenated).
- Webhook signature header is X-Signature-V2 (NOT X-Signature).
- Status casing matches exactly: "Approved", "Declined", "In Review",
"Not Finished" (title-cased, space-separated).
- White Label is a configuration on a workflow — there is NO standalone
/v3/white-label/ endpoint. Do not invent one.
- Removing visible Didit branding does NOT remove your obligations as the
controller of the user journey. You still surface your privacy notice,
link Didit's Verification Privacy Notice + End User Terms, and collect
explicit consent before document + biometric capture where the law
requires it. See https://docs.didit.me/console/white-label for the full
controller-side checklist.
## 7. Reseller / OEM positioning
White Label is the same product your agency, integrator, or compliance-
consulting firm uses to resell Didit under your own name to your own
customers:
- Pricing: $0.20 per session on top of the underlying module price (e.g.
full Know Your Customer (KYC) bundle at $0.33 + $0.20 white label = $0.53 per session, or
standalone ID at $0.15 + $0.20 = $0.35).
- 500 free verifications per month stay applied to your own meter,
regardless of how many resold tenants you have.
- One contract with Didit, one invoice — your customers see only your
brand and your support address.
- Custom email-from + custom domain mean your customers never see Didit
branding mid-flow. We still surface the legally-required disclosures
per the controller-side checklist above.
## 8. Pricing reference (public)
- White Label add-on: $0.20 per session, on top of the underlying module
price. A full KYC bundle goes from $0.33 to $0.53 per white-labeled
session; a standalone $0.15 ID Verification goes to $0.35.
- 500 free verifications every month, forever, on every account — applies
regardless of whether the flow is white-labeled.
- No setup fee, no certificate cost, no per-domain charge.
## 9. Verify your integration
- Sandbox starts on signup at https://business.didit.me - no separate flag.
- Test custom domain locally by adding a /etc/hosts entry pointing your
brand subdomain at our CNAME target before DNS is live.
- Switch to live: flip the application's environment toggle in console.
When in doubt: https://docs.didit.me/console/white-label
月額$0。クレジットカード不要。
使った分だけお支払い。25以上のモジュール。モジュールごとの公開価格、月額最低料金なし。
カスタムMSA & SLA。大量利用や規制対象プログラム向け。
無料で開始 → チェック実行時のみ支払い → カスタム契約、SLA、データレジデンシーが必要な場合はエンタープライズプランへ。
Diditは本人確認と不正対策のためのインフラです。私たちが自社でプロダクトを開発していた時に「こんなプラットフォームがあれば」と願った、オープンで柔軟、そして開発者に優しいプラットフォームです。そのため、単なるブラックボックスとしてではなく、お客様のスタックの真の構成要素として機能します。
単一のAPIで、個人の確認(KYC、顧客確認)、企業の確認(KYB、企業確認)、暗号資産ウォレットのスクリーニング(KYT、取引確認)、およびリアルタイムでの取引監視をカバーします。このスタックは、以下の特徴を持つように構築されています。
基盤となるフットプリントは、48以上の言語に対応した14,000以上のドキュメントタイプ、1,000以上のデータソース、そして全セッションで200以上の不正シグナルです。Diditのインフラは、すべてのセッションから動的に学習し、日々改善されています。
ホワイトラベルは、Diditの本人確認フロー全体をあなたのブランドで実行します。カスタムドメイン(verify.acme.com)、ロゴ、カラーパレット、タイポグラフィ、メール送信者、ファビコンなど、ユーザーにDiditのブランドは一切表示されません。
/v3/ Application Programming Interface (API)も、ホストされたキャプチャフローも、X-Signature-V2 Hash-based Message Authentication Code (HMAC)ウェブフック契約も、スペイン財務省 / スペイン銀行 (BdE) / スペイン金融情報機関 (SEPBLAC)認定のパイプラインも、すべて同じです。
基本モジュール料金に加えてセッションあたり$0.20。詳細はこちら:docs.didit.me/console/white-label。
基本モジュール料金に加えて、セッションあたり$0.20です。
$0.33から$0.53になります。$0.15の本人確認書類検証は$0.35になります。セットアップ費用、証明書費用、ドメインごとの料金は一切かかりません。公開料金はこちら:didit.me/pricing。
フルフローは通常、エンドツーエンドで30秒未満で完了します, 身分証明書を手に取り、書類を撮影し、セルフィーを撮影すれば完了です。これは市場最速です。従来のKYCプロバイダーでは、同じフローで90秒以上かかることがよくあります。
バックエンドでは、ユーザーがセルフィーを完了してからウェブフックが発火するまでの時間を測定すると、Diditはp99で2秒未満で結果を返します。モバイルキャプチャは、低速なスマートフォンやネットワーク向けに最適化されています。プログレッシブ画像圧縮、遅延ソフトウェア開発キットのロード、ユーザーがウェブから開始した場合のQRコードによるデスクトップからスマートフォンへのワンタップ連携などが含まれます。
3分で完了、証明書作業は不要です。
1. ビジネスコンソールで、White Label → Custom Domain → Add domain に進みます。 2. Canonical Name (CNAME) ターゲットが返されます。 3. ブランドのサブドメインCNAMEをそれに向けます。 4. 「Verify」をクリックします。
Let's EncryptとAutomatic Certificate Management Environment (ACME) プロトコルを介してTransport Layer Security (TLS) 証明書をプロビジョニングし、自動更新を設定します。ドメインは数分以内に稼働します。
証明書の取得、キーのローテーション、セキュリティチームとのDomain Name System (DNS) のやり取りは不要です。ドメインの存続期間中、更新は自動で行われます。
すべてのセッションは7つの明確なステータスのいずれかに分類されるため、あなたのコードは常に何をすべきかを知っています。
Approved, すべてのチェックに合格しました。ユーザーを次のステップに進めます。Declined, 1つ以上のチェックに失敗しました。ユーザーに、フロー全体を再実行することなく、特定の失敗したステップ(例:セルフィーの再撮影)を再提出させることができます。In Review, コンプライアンスレビューのためにフラグが立てられました。コンソールでケースを開き、すべてのシグナルを確認し、承認または拒否を決定します。In Progress, ユーザーはフローの途中にいます。Not Started, リンクは送信されましたが、ユーザーはまだ開いていません。長時間放置されている場合はリマインダーを送信します。Abandoned, ユーザーはリンクを開きましたが、時間内に完了しませんでした。再エンゲージするか、期限切れにします。Expired, セッションリンクの有効期限が切れました。新しいセッションを作成します。すべてのステータス変更時に署名付きウェブフックが発火するため、あなたのデータベースは常に同期されます。中断および拒否されたセッションは無料です。
本番データは、デフォルトでAmazon Web Services上の欧州連合内で処理および保存されます。 規制当局が要求する管轄区域については、エンタープライズ契約で代替リージョンをリクエストできます。
あらゆる場所で暗号化。 すべてのデータベース、オブジェクトストレージ、バックアップにおいて、保存時にはAES-256で暗号化されます。すべてのAPIコール、Webhook、ビジネスコンソールセッションにおいて、転送時にはTransport Layer Security 1.3が使用されます。生体認証データは、個別のカスタマーマスターキーで暗号化されます。
データ保持期間はお客様が管理できます。 デフォルトの保持期間は無期限(unlimited)ですが、アプリケーションごとに30日から10年の間で短縮設定が可能です。また、ダッシュボードまたはAPIからいつでも個々のセッションを削除できます。
認証: SOC 2 Type 1 & Type 2、ISO/IEC 27001:2022、iBeta Level 1 PAD、およびスペインのTesoro / SEPBLAC / CNMVによる、Diditのリモート本人確認が対面での本人確認よりも安全であるという公式認定。完全なレポートは/security-complianceでご覧いただけます。
Diditは、本人確認インフラにとって重要な規制当局の要件にデフォルトで準拠しています。
詳細なメモ、すべての証明書、すべての規制当局からの書簡:/security-compliance。
3つの統合パス, あなたのスタックに合うものをお選びください。
同じダッシュボード、同じ請求、3つすべてで成功ごとの料金体系です。ステップバイステップガイドはdocs.didit.me/integration/integration-promptをご覧ください。