Skip to main content
This walks through one complete verification: authenticate, create a customer, open a transaction, run the flow on the device, and read the decision. You need your account’s OAuth client credentials and API base URL. Both come from your chmod account manager.
1

Get an access token

All API calls are authenticated with a bearer token from your account’s OAuth endpoint. Tokens live for an hour; reuse one until it expires.
Response
2

Create the customer

A customer is the person, and it persists across transactions. Create one the first time you verify someone, then reuse the returned customer_id forever — that is what lets chmod compare a new selfie against the face you already enrolled.
Response
Store customer_id against your own user record.
3

Open a transaction

This is where you say what should be verified and what counts as acceptable. The response carries the sdk_token your app needs.
Response
Every field in config is optional and falls back to a documented default. The full configuration is on Create transaction.
4

Run the flow on the device

Pass the sdk_token to your app and hand it to the SDK. The SDK renders document capture, the liveness check and the result screen, then returns.
Full setup in iOS installation and Android installation.
5

Read the decision

When the analysis finishes, chmod calls your webhook. Fetch the transaction to get the verdict and the reasons behind it.
Response
decision is APPROVED, REJECTED or UNDETERMINED. When it is REJECTED, every reason is in issues[] with a stable code — see Issue codes.

Next

Create transaction

Every rule you can enforce, and what each one defaults to.

Webhooks

Receive decisions as they happen, and verify the signature.

Reading a result

Every field the transaction returns.

Errors

Status codes and what is safe to retry.