Mtumiaji anaandika namba yake ya kitambulisho cha kitaifa. Didit inaiangalia dhidi ya database ya serikali iliyoitoa katika nchi 36, na inalinganisha selfie yao na picha ya usajili pale ambapo usajili unarudisha picha.
CambodiaMinistry of Interior voter register$0.35Moja kwa moja
CanadaCanadian credit bureau records (FINTRAC dual-process)$3.95Moja kwa moja
ChileServicio de Registro Civil e Identificación$0.20Moja kwa moja
ChinaNCIIC (National Citizen Identity Information Center)$0.30Moja kwa moja
ColombiaRegistraduría General de la Nación / ANI$0.20Moja kwa moja
Costa RicaTribunal Supremo de Elecciones$0.20Moja kwa moja
DenmarkCPR register$1.39Moja kwa moja
Dominican RepublicJunta Central Electoral$0.05Moja kwa moja
EcuadorRegistro Civil del Ecuador$0.20Moja kwa moja
El SalvadorRNPN$0.20Moja kwa moja
FinlandDVV population register$2.10Moja kwa moja
FranceFrench residential and utility records$1.54Moja kwa moja
GuatemalaSAT$0.20Moja kwa moja
HondurasCNE$0.20Moja kwa moja
IndiaUIDAI (Aadhaar)$0.25Moja kwa moja
IndonesiaIndonesian population register via residential records$0.35Moja kwa moja
KenyaIPRS (Integrated Population Registration System)$3.15Moja kwa moja
MalaysiaJPN (National Registration Department)$0.35Moja kwa moja
MexicoRENAPO$0.20Moja kwa moja
NetherlandsDutch residential records$0.90Moja kwa moja
NigeriaNIMC / NIBSSNIN $0.20 / BVN $0.35Moja kwa moja
NorwayNorwegian residential records$2.42Moja kwa moja
PanamaTribunal Electoral / SIB$0.75Moja kwa moja
ParaguayRegistro del Estado Civil$0.20Moja kwa moja
PeruRENIEC$0.20Moja kwa moja
SingaporeSingapore credit bureau and utility records$4.30Moja kwa moja
South AfricaDepartment of Home Affairs$2.20Moja kwa moja
SwedenSkatteverket population register$0.35Moja kwa moja
ThailandDOPA civil registration$0.35Moja kwa moja
United KingdomUK credit bureau and financial services records$1.85Moja kwa moja
United StatesUS credit bureau and financial services records$0.27Moja kwa moja
UruguayDirección Nacional del Registro de Estado Civil$0.20Moja kwa moja
VenezuelaCNE$0.20Moja kwa moja
Upatikanaji na bei hutoka kwenye orodha ya njia za uzalishaji, si kutoka ukurasa huu. Nchi huwaka hapa mara tu inapoweza kuwashwa ndani ya mtiririko wako wa kazi; bei ni USD kwa jaribio lililojibiwa.
Inapatikana leo
Leo, rejista thelathini na sita zinajibu. Kila bei imechapishwa.
Kuanzia Argentina hadi Afrika Kusini, kila nchi kwenye orodha inapatikana na bei yake maalum ya nchi karibu nayo. Argentina, Nigeria, Panama na Afrika Kusini hurejesha picha ya rejista, kwa hivyo nchi hizo nne pia huendesha selfie, passive liveness na face match ndani ya utafutaji mmoja.
Jinsi inavyofanya kazi
Kutoka namba ya kitambulisho hadi mtumiaji aliyethibitishwa kwa hatua nne.
Hatua 01 / 04
01
Unda mtiririko wa kazi
Washa utafutaji kwa nchi zinazounga mkono. Chagua kinachotokea kwenye mechi isiyo kamili, kwenye kutolingana, na wakati rejista inakaa kimya. Weka idadi ya majaribio anayopata mtumiaji. Hakuna code inayohitajika.
Unganisha
Unganisha moja kwa moja na SDK zetu za Web, iOS, Android, React Native, au Flutter. Elekeza kwenye ukurasa uliopangishwa. Au tuma tu kiungo kwa mtumiaji wako — kwa barua pepe, SMS, WhatsApp, popote.
Mtumiaji anapitia mchakato
Didit huomba namba ya kitambulisho na maelezo machache kwa lugha rahisi na huangalia muundo kabla ya chochote kuondoka kwenye kifaa. Ambapo rejista inarejesha picha, tunapiga selfie, tunaendesha passive liveness juu yake, na kulinganisha hizo mbili.
Unapokea matokeo
Webhooks zilizotiwa saini za muda halisi huweka database yako sawa mara tu mtumiaji anapoidhinishwa, kukataliwa, au kutumwa kwa ukaguzi. Uliza API inapohitajika. Au fungua console na usome kila sehemu ambayo rejista ililinganisha.
Imejengwa kwa ajili ya waendelezaji · Imejengwa dhidi ya udanganyifu · Wazi kwa muundo
Uwezo sita. Njia moja ndani ya Uthibitishaji wa Kitambulisho.
Utafutaji usio wa hati si bidhaa tofauti. Ni njia moja unayowasha kwa kila nchi, karibu na upigaji picha wa hati na pochi za kitambulisho cha kidijitali, kwenye mkataba huo huo wa matokeo.
Nchi thelathini na sita zinajibu leo, kila moja kupitia shirika la serikali lililotoa namba: RENAPER nchini Argentina, RENIEC nchini Peru, NIMC na NIBSS nchini Nigeria, Idara ya Mambo ya Ndani nchini Afrika Kusini. Mtiririko wako wa kazi unasoma orodha sawa na ukurasa huu, kwa hivyo nchi mpya inaonekana siku inapokuwa tayari.
Ufikiaji wa utafutaji
Moja kwa moja kutoka kwenye katalogi ya mbinu
36
Rejista za moja kwa moja
4
Rudisha picha
0
Picha za hati zinazohitajika
Argentina
Bolivia
Brazil
Cambodia
Canada
Chile
China
Colombia
Costa Rica
Denmark
Dominican Republic
Ecuador
El Salvador
Finland
France
Guatemala
Honduras
India
Indonesia
Kenya
Malaysia
Mexico
Netherlands
Nigeria
Norway
Panama
Paraguay
Peru
Singapore
South Africa
Sweden
Thailand
United Kingdom
United States
Uruguay
Venezuela
Kila nchi iliyoorodheshwa inapatikana moja kwa moja. Kuingia kwa dashi, ikiwa kutatokea hapa, kumo kwenye katalogi lakini bado hakujawashwa.
02 · Mtumiaji anaandika nini
Namba ya kitambulisho na majina mawili. Hakuna kamera.
Kila nchi huomba sehemu halisi ambazo rejista yake inahitaji, kwa lugha rahisi. Ukaguzi wa muundo huendeshwa kwenye kifaa, kwa hivyo namba iliyoandikwa vibaya haifiki kamwe kwenye rejista na haikugharimu chochote.
Anachochapa mtumiaji
Department of Home Affairs
Namba ya kitambulisho yenye tarakimu 13
8001015009087Imethibitishwa
Jina la kwanza
Thandi
Jina la mwisho
Mokoena
Uthibitishaji wa umbizo hufanyika kabla ya chochote kuondoka kwenye kifaa. Namba iliyochapwa vibaya haifiki kamwe kwenye rejista na haitozwi kamwe.
03 · Selfie na face match
Linganisha selfie na picha ya rejista.
Ambapo rejista inarejesha picha, Didit hupiga selfie, huendesha passive liveness juu yake, na kulinganisha uso na picha hiyo. Zote tatu huendeshwa ndani ya bei ya utafutaji, si juu yake.
Selfie na kulinganisha uso
Ambapo rejista inarudisha picha
Picha ya rejista
Selfie
Liveness tulivuImefaulu
Kulinganisha uso98.6%
Gharama ya ziadaHakuna
04 · Fallbacks
Amua kinachotokea wakati jibu si safi.
Mechi isiyo kamili, kutolingana, na rejista ambayo haijawahi kujibu ni swichi tatu tofauti. Kila moja hurudi kwenye upigaji picha wa hati au kukataa, na kila moja inaonyesha gharama ya njia hiyo kabla ya kuihifadhi. Mtumiaji anapata jaribio moja kwa chaguo-msingi na hadi matano.
Rudi kwenye hati
Swichi moja kwa kila matokeo
Kulingana kwa sehemuUtafutaji + $0.15
Hakuna kulinganaUtafutaji + $0.15
Hakuna jibu kutoka kwa rejista$0.15 pekee
Majaribio kabla ya kurudi nyuma (chaguo-msingi / upeo)1 / 5
05 · Ushahidi wa kikao
Soma kila sehemu ambayo rejista ililinganisha.
Kikao hubeba safu moja kwa kila sehemu na uamuzi kamili, wa sehemu au usiolingana, chanzo kilichojibu, lini kilikaguliwa, majaribio mangapi yaliyochukua, na picha ya rejista ikiwa ipo.
Kulinganisha sehemu
Kwenye kipindi
Kulinganisha data
Jina kamiliSahihi
Tarehe ya kuzaliwaSahihi
Hali ya kitambulishoHalali
UraiaKiasi
Lebo za uhakikisho ni kwa ajili ya wakaguzi wako. Mtumiaji wa mwisho hazioni kamwe, jina la chanzo, au bei.
06 · Malipo
Lipa wakati rejista inajibu kweli.
Usajili unaojibu maswali ya bili, iwe umelingana au la. Upigaji picha wa hati hulipishwa tu ikiwa mtumiaji atashindwa. Usajili usio na jibu na namba iliyoandikwa vibaya havilipishwi kabisa.
Kinachotozwa
Afrika Kusini, USD kwa kila jaribio lililojibiwa
$2.20
Rejista imejibu — inalingana, kiasi au hakunaImetozwa
Mtumiaji amerudi kwenye upigaji picha wa hatiImetozwa
Rejista haikujibu kamweBure
Nambari imeshindwa ukaguzi wa umbizoBure
Kila kiwango ni bei ya rejareja ya umma ya USD na inajumuisha selfie, liveness na utambuzi wa uso ambapo rejista inarudisha picha. Upigaji picha wa hati unatozwa tu wakati mtumiaji anarudi nyuma.
Unganisha
Ombi moja. Matokeo yaliyotiwa saini yanarudi.
Anzisha session, mpeleke mtumiaji huko, na uthibitishe webhook iliyotiwa saini matokeo yanapofika. Njia halisi aliyotumia mtumiaji inarudi kwenye matokeo.
Anzisha uthibitishaji usio wa hati kwa prompt moja.
Bandika block iliyo hapa chini kwenye Claude Code, Cursor, Codex, Devin, Aider, au Replit Agent. Jaza kishika nafasi cha my_stack na framework yako, lugha na matumizi. Agent huwezesha Didit, huwasha njia kwa kila nchi, huunganisha webhook, na hupeleka.
didit-integration-prompt.md
# Didit non-document verification — integrate in 5 minutes
You are adding non-document identity verification to my_stack. The user types a
national ID number plus a few personal details, and Didit checks them against
the government database that issued the number. Every URL, header, and enum
value below is canonical — do not paraphrase or "improve" them.
## 1. Provision an account
- Sign up: https://business.didit.me (no credit card required).
- Grab the API key for your application from the console.
## 2. Read the methods catalog first
Availability is server-driven per country. Never hard-code a country list.
The catalog is not a public REST endpoint. Read it one of two ways:
- Business Console (signed in): your application -> ID Verification ->
Countries tab. https://docs.didit.me/console/id-verification-methods
- Didit MCP server tool didit_workflow_get_id_verification_methods_catalog,
authenticated with the same x-api-key; pass country (ISO 3166-1 alpha-3)
to narrow it to one country. https://docs.didit.me/integration/mcp/tools
- Public mirror of the coverage table (no auth, read-only):
https://docs.didit.me/core-technology/id-verification/verification-methods#coverage
The catalog tells you, per ISO 3166-1 alpha-3 country code:
- whether id_lookup is available
- the source label and the public USD rate per answered attempt (36 countries
are live at the time of this prompt, from Argentina to South Africa)
- the exact request fields to ask the user for, with their format rules
- the response fields that come back, and which of them are optional
## 3. Create a workflow with the ID Verification (OCR) feature
POST https://verification.didit.me/v3/workflows/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
The ID Verification feature's enum value is OCR (UPPERCASE — strict enum;
there is no ID_VERIFICATION alias and the API rejects it). Non-document
lookup is its id_lookup method, configured per country under config.methods
on that same feature entry, in the same request. Keys are ISO 3166-1 alpha-3.
An omitted country, or an omitted methods key, means document only.
{
"workflow_label": "Non-document onboarding",
"features": [
{
"feature": "OCR",
"config": {
"methods": {
"ZAF": {
"document": { "enabled": true },
"id_lookup": {
"enabled": true,
"max_attempts": 1,
"skip_liveness_and_face_match": false,
"on_partial_match": "fallback_to_document",
"on_no_match": "fallback_to_document",
"on_provider_error": "fallback_to_document",
"response_fields": ["gender", "citizenship", "registry_portrait"]
}
}
}
}
}
]
}
Response: the workflow uuid — use it as workflow_id in step 4.
Rules that the API enforces:
- every fallback value is either fallback_to_document or decline
- max_attempts is an integer from 1 to 5, default 1
- skip_liveness_and_face_match is only accepted where the source returns a
portrait; elsewhere it is rejected
- response_fields lists the OPTIONAL fields you want stored. Required fields
are always stored and cannot be removed
- a country whose id_lookup the catalog does not mark available is rejected
- a country with no method enabled is rejected at publish time
## 4. Create a session
POST https://verification.didit.me/v3/session/
-H "x-api-key: <your-api-key>"
-H "Content-Type: application/json"
-d '{ "workflow_id": "<id from step 3>", "vendor_data": "<your user id>" }'
Response: 201 with url (the hosted verification link), session_token and
session_id. Redirect the user to url, or open it in the SDK. The field is
named url — there is no session_url and no verification_url.
Didit asks the user for the request fields in plain language, runs the
client-side format check, then queries the registry.
Where the registry returns a portrait (Argentina, Nigeria, Panama, South
Africa), Didit also takes a selfie, runs passive liveness on it, and
face-matches it to that portrait. All of it is inside the lookup price.
## 5. Webhooks
Register a destination (console -> API & Webhooks, or
POST https://verification.didit.me/v3/webhook/destinations/ with
webhook_version "v3" and subscribed_events ["status.updated"]) and store the
secret_shared_key it returns. Verify every delivery:
Header: X-Signature-V2 (NOT X-Signature, NOT X-Signature-Simple)
Algorithm: HMAC-SHA256, hex digest, over the CANONICAL JSON of the payload:
parse the body, sort keys recursively, serialise compact with
Unicode preserved and whole-valued floats as integers. Do NOT
hash the raw request bytes — that is the v1 X-Signature
algorithm and fails for V2 whenever whitespace or key order
differs from the canonical form.
Freshness: the signed body field timestamp is the dispatch time (Unix
seconds, refreshed on every retry). Reject when
abs(now - timestamp) > 300 seconds, and reject when the
X-Timestamp header does not equal it. The header is not
covered by the signature, so it must never be the only replay
check: a captured delivery replays with just that header
refreshed.
Compare: constant-time (crypto.timingSafeEqual)
Reference handler (Express) — use it as written:
const crypto = require("crypto");
// X-Signature-V2 signs canonical JSON: keys sorted as strings, compact,
// Unicode preserved. Emit the sorted entries directly - rebuilding an object
// would reorder integer-like keys ("10", "2"). Never hash req.rawBody.
const canonical = (v) =>
Array.isArray(v) ? "[" + v.map(canonical).join(",") + "]"
: v && typeof v === "object"
? "{" + Object.keys(v).sort()
.map((k) => JSON.stringify(k) + ":" + canonical(v[k])).join(",") + "}"
: JSON.stringify(v);
app.post("/webhooks/didit", express.json(), (req, res) => {
// Freshness: the signed body timestamp (refreshed on retry) must be recent
// and X-Timestamp must agree - the header alone is unsigned and replayable.
const ts = Number(req.body?.timestamp);
if (!ts || String(ts) !== req.headers["x-timestamp"] ||
Math.abs(Date.now() / 1000 - ts) > 300) return res.sendStatus(401);
const expected = crypto.createHmac("sha256", SECRET)
.update(canonical(req.body), "utf8").digest("hex");
const sig = String(req.headers["x-signature-v2"] ?? "");
const valid = sig.length === expected.length &&
crypto.timingSafeEqual(Buffer.from(sig), Buffer.from(expected));
if (!valid) return res.sendStatus(401);
const { status, decision } = req.body;
// One entry per ID Verification node; pick yours by node_id when you run several.
const [idv] = decision?.id_verifications ?? [];
// idv.verification_method: "document" | "id_lookup" | "wallet"
res.sendStatus(200);
});
Body fields you will use: session_id, status, webhook_type, workflow_id,
vendor_data, decision.
Status values: Approved, Declined, In Review, In Progress, Not Started,
Abandoned.
## 6. Reading the result
The decision is the V3 shape: every feature result is a plural array with one
entry per workflow node. ID Verification results live in
decision.id_verifications[] — there is no singular decision.kyc (that is the
V2 shape) and no decision.id_verification. Select your entry by node_id (the
id of your ID Verification node in the workflow graph); with a single ID step,
take index 0. Each entry carries, next to the document fields:
verification_method "document" | "id_lookup" | "wallet"
assurance "documentary" | "data_match" | "cryptographic"
id_lookup source label, checked_at, attempts, outcome, one
comparison row per field with match / partial /
no_match, and the registry portrait reference when
there is one; null on document entries
fallback_from { method, reason, action } when the session fell
back to document capture or was declined; else null
A non-document entry that succeeds is assurance data_match, never
documentary. The fallbacks only govern unsuccessful lookups (partial match,
no match, provider error): a lookup that matches is accepted as the ID result
and never reaches them, so switching them to decline does not add documentary
evidence. If your risk policy needs documentary assurance for a segment, do
not enable id_lookup for that segment's country: configure
"document": { "enabled": true } alone (omit the id_lookup key, or set its
enabled to false) and route that segment to a workflow of its own when other
users may keep the lookup. As a final guard, treat any id_verifications[]
entry whose assurance is not documentary as failing that policy.
Field-by-field reference: https://docs.didit.me/reference/data-models#id-verification
## 7. Billing — what actually bills
- a registry that answered bills the lookup. Match, partial match and no
match all count as answered
- document capture bills on top when the user falls back
- a source that never answered is not billed
- a number that fails the client-side format check never reaches the registry
and is neither counted nor billed
## 8. Hard rules — do not change
- base URL for v3 endpoints: verification.didit.me
- auth header: x-api-key (lowercase, hyphenated)
- webhook headers: X-Signature-V2 plus X-Timestamp; canonical JSON, never
raw bytes; freshness from the signed body timestamp
- feature enum: OCR (uppercase) — the ID Verification feature; per-country
methods go under its config.methods
- method keys: document, id_lookup, wallet (lowercase, snake_case)
- country keys: ISO 3166-1 alpha-3, uppercase
- result path: decision.id_verifications[] (array), never decision.kyc
## 9. Verify your integration
- run one session per configured country in sandbox
- assert the id_verifications[] entry for your node has verification_method
id_lookup on the happy path
- force a no-match and assert the fallback you configured actually fires
- for a segment that needs documentary assurance, run a lookup that matches
against that segment's workflow and assert its entry has
verification_method document and assurance documentary
- assert your webhook accepts a correctly signed payload with reordered
keys, whitespace and integer-like metadata keys ("10" before "2"), and
rejects a wrong X-Signature-V2, a payload whose signed timestamp is older
than 300 seconds, and that same stale payload with only the X-Timestamp
header refreshed
Docs: https://docs.didit.me/integration/integration-prompt
Inatii kwa muundo
Fungua nchi mpya kwa kubofya mara moja. Tunafanya kazi ngumu.
Tunafungua kampuni tanzu za ndani, tunapata leseni, tunafanya majaribio ya kupenya, tunapata vyeti, na tunalingana na kila kanuni mpya. Ili kusafirisha uthibitishaji katika nchi mpya, geuza swichi. Nchi 220+ ziko hewani, zinakaguliwa na kupimwa kila robo mwaka, mtoa huduma pekee wa utambulisho ambaye serikali ya nchi mwanachama wa EU imemwita rasmi kuwa salama zaidi kuliko uthibitishaji wa ana kwa ana.
Anza bure. Lipa kadri unavyotumia. Kuza hadi Enterprise.
Uthibitishaji 500 bila malipo kila mwezi, milele. Kisha lipa tu moduli inapofanya kazi. Mikataba maalum, uhifadhi wa data, na makubaliano ya kiwango cha huduma (SLAs) kwenye Enterprise.
Bure
$0/ mwezi · hakuna kadi
Kwa ajili ya kuunda, kujaribu, na watumiaji wako wa kwanza.
Kila kitu unachohitaji kuanzia:
Uthibitishaji kamili wa KYC 500 kila mwezi
Kitambulisho, uhai, kulinganisha uso, kifaa & IP
Ishara za udanganyifu 200+, orodha nyeusi, marudio
KYC inayoweza kutumika tena kwenye mtandao wa Didit
Mjenzi wa mtiririko wa kazi, usimamizi wa kesi, SDKs
Usaidizi wa AIAI agent ndani ya console, docs, na jumuiya.