Ruka hadi maudhui makuu
Didit Yakusanya $2M na Kujiunga na Y Combinator (W26)
Didit
Utambuzi wa Bot

Wazuie "boti" kwa lango la Passive Liveness. Fremu moja. Uamuzi mmoja.

Ukaguzi mmoja wa Utendaji Tulivu mbele ya kitendo chochote cha thamani ya juu. Roboti hazina uso wa kuonyesha — haziwezi kupita. Uamuzi wa chini ya sekunde mbili, $0.10 kwa kila ukaguzi, 500 bure kila mwezi.

Inaungwa mkono na
Y Combinator
GBTC Finance
Bondex
Crnogorski Telekom
UCSF Neuroscape
Shiply
Adelantos

Inaaminika na mashirika 2,000+ duniani kote.

Mrundikano wa giza usioeleweka wa utambuzi wa roboti — paneli nne zinazoelea, zisizo na uwazi za kioo cheusi katika mtazamo wa 3D kwenye nyeusi safi, zilizounganishwa na mstari wima wa Didit Blue unaong'aa na kuwekewa fremu na mabano ya skana yanayong'aa. Kila paneli hubeba motifu moja ndogo, nyeupe-nyeupe isiyo dhahiri ya lango (kichwa cha roboti, wimbi bapa, gridi ya hitilafu, muda wa kutiliwa shaka).

Kwa nini CAPTCHA iliacha kufanya kazi

Mashamba ya "solver" yanashinda CAPTCHA. Liveness bado inaomba uso.

Mashamba ya kibiashara ya kutatua CAPTCHA husafisha hCaptcha na reCAPTCHA Enterprise kwa sehemu za senti. Utendaji Tulivu huuliza kitu ambacho hati haina — binadamu halisi mbele ya kamera halisi. $0.10 kwa kila lango, chini ya sekunde mbili, 500 bure kila mwezi.

Jinsi inavyofanya kazi

Kutoka kujisajili hadi mtumiaji aliyethibitishwa kwa hatua nne.

  1. Hatua 01

    Unda mtiririko wa kazi

    Chagua ukaguzi unaotaka — Kitambulisho, uhai, kulinganisha uso, vikwazo, anwani, umri, simu, barua pepe, maswali maalum. Ziburute kwenye mtiririko kwenye dashibodi, au tuma mtiririko huo huo kwa API yetu. Panga kwa masharti, fanya majaribio ya A/B, hakuna msimbo unaohitajika.

  2. Hatua 02

    Unganisha

    Pachika kiasili na Web, iOS, Android, React Native, au Flutter SDK yetu. Elekeza kwenye ukurasa uliopangishwa. Au tuma tu mtumiaji wako kiungo — kwa barua pepe, SMS, WhatsApp, popote. Chagua kinachofaa mfumo wako.

  3. Hatua 03

    Mtumiaji anapitia mchakato

    Didit huandaa kamera, vidokezo vya mwanga, uhamishaji wa simu, na ufikiaji. Wakati mtumiaji yuko kwenye mtiririko, tunapata alama za ishara 200+ za udanganyifu kwa wakati halisi na kuthibitisha kila sehemu dhidi ya vyanzo vya data vya mamlaka. Matokeo chini ya sekunde mbili.

  4. Hatua 04

    Unapokea matokeo

    Webhooks zilizotiwa saini kwa wakati halisi huweka hifadhidata yako sawa mara tu mtumiaji anapoidhinishwa, kukataliwa, au kutumwa kwa ukaguzi. Piga API inapohitajika. Au fungua koni ili kukagua kila kipindi, kila ishara, na kudhibiti kesi kwa njia yako.

Imejengwa kwa ajili ya lango · Bei kama miundombinu

Ukaguzi mmoja wa Passive Liveness. $0.10 kwa kila lango.

Lango la bot ni muundo — uso, uchunguzi wa awali, uhai, uamuzi. Washa kila moduli kwa kila mtiririko wa kazi katika Mjenzi wa Mtiririko wa Kazi.
01 · Eneo la mashambulizi

Ambapo bots huonekana — na ambapo lango huenda.

Fomu za kujisajili, bao za wanaoongoza, madai ya airdrop / tokeni, malipo ya rufaa, sehemu za maoni, foleni za tiketi. Mtiririko wa kazi wa Mjenzi wa Mtiririko wa Kazi hulinda kila eneo. Anzisha tu kwenye vitendo vinavyo muhimu — usomaji wa kila siku hauhitaji lango.
Moduli ya Mratibu wa Mtiririko wa Kazi
02 · Lango la uhai

Binadamu halisi mbele ya kamera halisi.

Uhai Usio na Kazi humwomba mtumiaji asimame tuli kwa fremu moja. Mfumo hurejesha uamuzi chini ya sekunde mbili kwa $0.10 kwa kila ukaguzi. Hakuna mafumbo, hakuna utambuzi wa herufi, hakuna athari za panya za tabia — fremu tu na uamuzi. iBeta Level 1 PAD imethibitishwa dhidi ya ISO/IEC 30107-3.
Moduli ya uhai
03 · Ulinzi wa vekta ya mashambulizi

Kila vekta ya bot — uamuzi sawa.

Chrome isiyo na kichwa yenye uwasilishaji uliopangwa, mashamba ya otomatiki ya kivinjari, sindano za uso za AI za kamera pepe, marudio ya skrini yaliyorekodiwa awali, uwasilishaji wa picha pekee bila kamera iliyounganishwa, deepfakes zinazozalishwa na AI — zote zimezuiwa. Mfumo hujaribiwa tena kwa kujitegemea katika iBeta kila mwaka kadri vekta mpya zinavyoonekana porini.
Jinsi Uhai unavyofanya kazi
04 · IP + uchunguzi wa awali wa kifaa

Ruka kamera kwenye bots zilizo wazi.

Uchambuzi wa Kifaa na IP hurejesha alama 0–100 pamoja na Virtual Private Network (VPN), Tor, nambari ya Mfumo Huru wa kituo cha data (ASN), kivinjari kisicho na kichwa, na bendera za kasi ya kifaa. $0.03 kwa kila simu, chini ya 100ms. Kataa mapema wakati mtandao umepangwa wazi; tumia tu bajeti ya uhai kwa wanadamu wanaowezekana.
Moduli ya Uchambuzi wa Kifaa na IP
05 · KYC inayoweza kutumika tena

Mara moja binadamu. Daima binadamu.

Watumiaji ambao tayari wamepitisha kipindi kilichothibitishwa na Didit wanaweza kurudia kitambulisho bila gharama kupitia KYC Inayoweza Kutumika Tena. Hakuna ruhusa ya pili ya kamera, hakuna msuguano — lango linakaa mbele ya trafiki isiyojulikana tu. Bure milele.
Moduli ya KYC Inayoweza Kutumika Tena
06 · Bomba la webhook

Uamuzi uliotiwa saini. Matawi matatu. Imekamilika.

Webhook iliyotiwa saini inatua na uamuzi — Imeidhinishwa, Imekataliwa, Inakaguliwa, Haijamalizika. Thibitisha X-Signature-V2 na Hash-based Message Authentication Code (HMAC) SHA-256 kabla ya kusoma mwili. Ishara 200+ za udanganyifu zimefunuliwa bila gharama ya ziada. Panga hatua ya awali ipasavyo.
Rejea ya webhook
Unganisha

Kipindi kimoja. Uamuzi mmoja uliotiwa saini. Matawi matatu.

Fungua lango. Soma uamuzi uliotiwa saini. Ruhusu, zuia, au alika jaribio tena.
POST /v3/session/Uhai
$ curl -X POST https://verification.didit.me/v3/session/ \
  -H "x-api-key: $DIDIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{
    "workflow_id": "wf_bot_gate",
    "vendor_data": "signup-918",
    "metadata": { "surface": "signup_form" }
  }'
201Imeundwa{ "session_url": "verify.didit.me/..." }
Zuia hatua hadi "webhook" itue status: Approved.nyaraka →
POST /webhooks/diditUamuzi
// X-Signature-V2 verified upstream
if (payload.status === "Imeidhinishwa") {
  ruhusuKujisajili(payload.data_ya_muuzaji);
} vinginevyo ikiwa (payload.status === "Imekataliwa") {
  punguzaIP(payload.uchambuzi_wa_ip.ip);
  zuiaNaAndika(payload.data_ya_muuzaji);
}
200OKhali Imeidhinishwa · Imekataliwa · Inakaguliwa · Haijakamilika
Thibitisha X-Signature-V2 kabla ya kusoma "payload".nyaraka →
Ujumuishaji tayari kwa wakala

Tuma lango la bot la Passive Liveness kwa haraka moja.

Bandika kwenye Claude Code, Cursor, Codex, Devin, Aider, au Replit Agent. Jaza stack yako. Agent huunganisha kichochezi, hufungua kipindi cha uhai, huthibitisha webhook, na huzuia kitendo.
didit-integration-prompt.md
You are integrating Didit Passive Liveness as a bot-gate on a high-value action — sign-up, leaderboard submission, airdrop / token claim, referral payout, comment, or ticket queue. Bots cannot pass Passive Liveness because they have no face to present to the camera. One API call. One signed webhook. One decision.

WHY THIS SHAPE
  - Bots scale because they cost nothing per attempt. CAPTCHA stops the dumbest ones but commercial solver farms beat hCaptcha and reCAPTCHA Enterprise at fractions of a cent per solve.
  - Passive Liveness asks for something a script does not have: a live human face in front of a real camera. The model decides on one frame, in under two seconds, with no user interaction beyond "hold still".
  - $0.10 per check (Passive Liveness module). 500 verifications free every month. Combine with $0.03 IP / device pre-screen to keep the camera off the obvious bots and the budget on real candidates.

PRE-REQUISITES
  - Production API key from https://business.didit.me (sandbox key in 60 seconds, no credit card).
  - A webhook endpoint with HMAC SHA-256 verification of the X-Signature-V2 header using your webhook secret.
  - A Workflow Builder workflow containing the Passive Liveness module — optionally Device & IP Analysis pre-step.
  - The high-value action wrapped in a server-side gate that defaults to BLOCK and only unblocks on a verified webhook with status: Approved.

STEP 1 — (Optional) Cheap IP / device pre-screen
  Before opening a camera, score the network with Device & IP Analysis ($0.03 / call, under 100ms).
  If the score is low and no datacenter / VPN / scripted-user-agent flags fire, run Step 2.
  If the score is high or any of those flags fire, skip the liveness call and decline up-front — this saves the camera budget for plausible humans.

STEP 2 — Open a Passive Liveness session
  POST https://verification.didit.me/v3/session/
  Headers:
    x-api-key: <your api key>
    Content-Type: application/json
  Body:
    {
      "workflow_id": "<wf id with the Passive Liveness module>",
      "vendor_data": "<your action / user id, max 256 chars>",
      "callback": "https://<your-app>/bot-gate/callback",
      "metadata": {
        "surface": "signup_form",
        "action_id": "<your internal reference>"
      }
    }

  Response: 201 Created with a hosted session URL. Redirect inline (web) or open in a Software Development Kit (SDK) webview (mobile). The action stays BLOCKED on your side until the signed webhook lands.

STEP 3 — Read the signed webhook
  Didit POSTs the verdict. Verify X-Signature-V2 (HMAC SHA-256 of the raw body using your webhook secret) BEFORE reading the JSON.

  Payload (excerpted):
    {
      "session_id": "<uuid>",
      "vendor_data": "<your action / user id>",
      "status": "Approved",
      "liveness": { "status": "Approved" }
    }

  Session status enum (exact case, Title Case With Spaces): Approved | Declined | In Review | Resubmitted | Expired | Not Finished | Kyc Expired | Abandoned.

STEP 4 — Branch the action
  Approved      → allow the sign-up / claim / submission.
  Declined      → block the action. Log liveness warnings (image-only / virtual-cam / replay / deepfake) and throttle the source IP.
  Not Finished  → invite the user to retry with a fresh session URL.
  Expired       → session timed out. Resend the link.
  Abandoned     → the user closed the flow before completing. Resend the link.

STEP 5 — (Optional) Replay Reusable Know Your Customer (KYC) for known humans
  If a user has previously completed a Didit-verified session, a fresh liveness check is not required for re-entry — they can replay their verified credential at no cost via Didit Reusable KYC. Use the user's existing session_id to confirm enrollment and skip Step 2. Free forever.

WEBHOOK EVENT NAMES
  - Sessions: standard session webhook. One endpoint, status field tells you where in the lifecycle.
  - Verify X-Signature-V2 (HMAC SHA-256) on every payload.

WHAT GETS BLOCKED
  - Headless Chrome with scripted form submission
  - Browser-automation farms (Puppeteer, Playwright, Selenium)
  - Image-only submissions (no camera attached)
  - Virtual-camera AI face injectors
  - Pre-recorded screen replays
  - Print or paper attacks
  - Silicone / latex masks
  - AI-generated deepfake faces

  All independently tested at iBeta and certified at Level 1 Presentation Attack Detection (PAD) against the full ISO/IEC 30107-3 catalogue. Re-tested every year.

CONSTRAINTS
  - Session statuses use Title Case With Spaces. Never use UPPER_SNAKE_CASE for session verdicts — that's the Transactions API.
  - Default to BLOCK on the server. Only unblock when the verified webhook says Approved.
  - 200+ fraud signals are evaluated on every session at no extra cost — read them off the decision payload, don't re-query.

Read the docs:
  - https://docs.didit.me/sessions-api/create-session
  - https://docs.didit.me/core-technology/liveness/overview
  - https://docs.didit.me/core-technology/ip-analysis/overview
  - https://docs.didit.me/core-technology/reusable-kyc/overview
  - https://docs.didit.me/integration/webhooks

Start free at https://business.didit.me — sandbox key in 60 seconds, 500 verifications free every month, no credit card.
Unahitaji maelezo zaidi? Tazama nyaraka kamili za moduli.docs.didit.me →
Inatii kwa muundo

Fungua nchi mpya kwa kubofya mara moja. Tunafanya kazi ngumu.

Tunafungua kampuni tanzu za ndani, tunapata leseni, tunafanya majaribio ya kupenya, tunapata vyeti, na tunalingana na kila kanuni mpya. Ili kusafirisha uthibitishaji katika nchi mpya, geuza swichi. Nchi 220+ zinafanya kazi, zinakaguliwa na kujaribiwa kila robo mwaka — mtoa huduma pekee wa utambulisho ambaye serikali ya nchi mwanachama wa EU imemwita rasmi kuwa salama zaidi kuliko uthibitishaji wa ana kwa ana.
Soma jalada la usalama na utiifu
Sanduku la majaribio la kifedha la EU
Tesoro · SEPBLAC · BdE
ISO/IEC 27001
Usalama wa habari · 2026
SOC 2 · Type I
AICPA · 2026
iBeta Level 1 PAD
NIST / NIAP · 2026
GDPR
EU 2016/679
DORA
EU 2022/2554
MiCA
EU 2023/1114
AMLD6 · eIDAS 2.0
Inalingana na EU kwa muundo

Namba za uthibitisho

Namba za uthibitisho
  • iBeta L1
    Utambuzi wa Mashambulizi ya Uwasilishaji uliothibitishwa kwa kujitegemea — hujaribiwa tena kila mwaka.
  • <0s
    Uamuzi wa mwisho hadi mwisho kwenye Android ya kiwango cha chini.
  • $0.00
    Kwa kila ukaguzi wa Passive Liveness. $0.03 uchunguzi wa awali wa IP wa hiari juu.
  • 0
    Uthibitishaji wa bure kila mwezi, kwenye kila akaunti.
Ngazi tatu, orodha moja ya bei

Anza bure. Lipa kwa matumizi. Panua hadi Biashara.

Uthibitishaji 500 bila malipo kila mwezi, milele. Lipa kadri unavyotumia kwa uzalishaji. Mikataba maalum, makazi ya data, na SLA (Mikataba ya Kiwango cha Huduma) kwenye Biashara.
Bure

Bure

$0 / mwezi. Hakuna kadi ya mkopo inayohitajika.

  • Kifurushi cha KYC cha bure (Uthibitishaji wa Kitambulisho + Uhai Usio na Kazi + Kulinganisha Uso + Uchambuzi wa Kifaa na IP) — 500 / mwezi, kila mwezi
  • Watumiaji Waliozuiliwa
  • Kugundua Marudio
  • Ishara 200+ za udanganyifu kwenye kila kipindi
  • KYC inayoweza kutumika tena kwenye mtandao wa Didit
  • Jukwaa la Usimamizi wa Kesi
  • Mjenzi wa Mtiririko wa Kazi
  • Hati za umma, sandbox, SDKs, seva ya MCP (Model Context Protocol)
  • Usaidizi wa jamii
Maarufu zaidi
Lipa kwa matumizi

Kulingana na Matumizi

Lipa tu kwa kile unachotumia. Moduli 25+. Bei ya umma kwa kila moduli, hakuna ada ya chini ya kila mwezi.

  • KYC kamili kwa $0.33 (Kitambulisho + Biometriska + IP / Kifaa)
  • Hifadhidata 10,000+ za AML — vikwazo, PEPs, vyombo vya habari hasi
  • Vyanzo 1,000+ vya data ya serikali kwa Uthibitishaji wa Hifadhidata
  • Ufuatiliaji wa Miamala kwa $0.02 kwa kila muamala
  • KYB ya Moja kwa Moja kwa $2.00 kwa kila biashara
  • Uchunguzi wa Wallet kwa $0.15 kwa kila ukaguzi
  • Mtiririko wa uthibitishaji wa Whitelabel — chapa yako, miundombinu yetu
Biashara

Biashara

MSA & SLA maalum. Kwa idadi kubwa na programu zilizodhibitiwa.

  • Mikataba ya kila mwaka
  • MSA, DPA, na SLA maalum
  • Kituo maalum cha Slack na WhatsApp
  • Wakaguzi wa mikono kwa mahitaji
  • Masharti ya muuzaji na white-label
  • Vipengele vya kipekee na ushirikiano wa washirika
  • CSM aliyetajwa, ukaguzi wa usalama, usaidizi wa kufuata

Anza bure → lipa tu wakati ukaguzi unafanyika → fungua Biashara kwa mkataba maalum, SLA, au makazi ya data.

FAQ

Maswali ya kawaida

Miundombinu ya utambulisho na udanganyifu.

API moja kwa KYC, KYB, Ufuatiliaji wa Miamala, na Uchunguzi wa Wallet. Unganisha kwa dakika 5.

Uliza AI ifupishe ukurasa huu