Face Active Liveness
The SDK runs three random challenges on the device and sends the best selfie to the Face Active Liveness API, which returns an HMAC-SHA256 signed verdict. Each finalized session costs 1 IC.
Call
- Flutter
- Web
- iOS
- Android
- React Native
import 'package:iapp_ekyc_sdk/iapp_ekyc_sdk.dart';
final client = IappEkycClient(apiKey: 'YOUR_API_KEY');
final liveness = await ActiveLivenessView.start(context, client: client);
if (liveness.verdict.passed) {
// Forward liveness.verdict + liveness.signature to YOUR backend,
// verify the HMAC there, then proceed with onboarding.
}
import { IappEkyc } from '@iapp-technology/ekyc-sdk';
const ekyc = new IappEkyc({ apiKey: 'YOUR_API_KEY' });
const liveness = await ekyc.startActiveLiveness({
mount: document.getElementById('ekyc-mount'),
});
if (liveness.verdict.passed) {
// Forward liveness.verdict + liveness.signature to your backend for verification.
}
// iOS (Swift; Objective-C also supported)
let config = IappEkycConfig(apiKey: "YOUR_API_KEY", flow: .activeLiveness)
IappEkycSdk.present(from: self, config: config) { result in
// Verify verdictJSON + signature on YOUR backend before trusting `passed`.
}
// Android (Kotlin; Java also supported)
ekyc.launch(IappEkycRequest.ActiveLiveness(config))
// React Native
<IappEkycFlow flow="activeLiveness" apiKey="YOUR_API_KEY"
onResult={handleResult} onError={handleError} onCancel={close} />
Install: Getting started for Flutter and Web, iOS, Android & React Native for the native wrappers and camera permission.
Result
The result carries the server's verdict and signature; the on-device outcome only guides the UI.
A modified client can fake on-device challenge results. Your backend must recompute HMAC-SHA256(secret, canonicalJSON(verdict)) and compare it to signature before it trusts verdict.passed. See the signature verification example.
How the session works
- Face lock: exactly one frontal face, large and centered enough, held steady before the challenges begin.
- Challenges: three distinct challenges drawn at random from blink, turn left, turn right and smile. A blink must close then open, a turn must reach at least 18° of yaw and return to center, a smile must be held.
- Restarts: losing the face, a second face in the frame or a change of identity restarts the current challenge; repeated restarts or timeouts fail the session.
- Selfie: every sharp, frontal, eyes-open frame is scored by sharpness and face size; the best one is sent to the server.
- Verdict: the server validates the challenge log, re-runs passive liveness on the selfie and signs the verdict.
The full liveness specification is in the SDK source.