Skip to main content

Face Active Liveness

The SDK runs three random challenges on the device and sends the best selfie to the Face Active Liveness API, which returns an HMAC-SHA256 signed verdict. Each finalized session costs 1 IC.

Call​

import 'package:iapp_ekyc_sdk/iapp_ekyc_sdk.dart';

final client = IappEkycClient(apiKey: 'YOUR_API_KEY');

final liveness = await ActiveLivenessView.start(context, client: client);

if (liveness.verdict.passed) {
// Forward liveness.verdict + liveness.signature to YOUR backend,
// verify the HMAC there, then proceed with onboarding.
}

Install: Getting started for Flutter and Web, iOS, Android & React Native for the native wrappers and camera permission.

Result​

The result carries the server's verdict and signature; the on-device outcome only guides the UI.

Trust only the signed verdict

A modified client can fake on-device challenge results. Your backend must recompute HMAC-SHA256(secret, canonicalJSON(verdict)) and compare it to signature before it trusts verdict.passed. See the signature verification example.

How the session works
  • Face lock: exactly one frontal face, large and centered enough, held steady before the challenges begin.
  • Challenges: three distinct challenges drawn at random from blink, turn left, turn right and smile. A blink must close then open, a turn must reach at least 18° of yaw and return to center, a smile must be held.
  • Restarts: losing the face, a second face in the frame or a change of identity restarts the current challenge; repeated restarts or timeouts fail the session.
  • Selfie: every sharp, frontal, eyes-open frame is scored by sharpness and face size; the best one is sent to the server.
  • Verdict: the server validates the challenge log, re-runs passive liveness on the selfie and signs the verdict.

The full liveness specification is in the SDK source.

© 2026 iApp Technology Co., Ltd.TermsPrivacyStatussale@iapp.co.th