1
Your backend identifies itself
Your server exchanges its client credentials for a short-lived access token. That token authenticates every call your backend makes to chmod for the next hour. It never leaves your server.
2
Your backend registers the person
It creates a customer: chmod’s persistent record of one person. You get back a
customer_id, and you store it against your own user — once, forever. Every later verification of the same person reuses it, which is what lets chmod compare a new selfie against the face it enrolled the first time and notice when a document contradicts an earlier one.3
Your backend opens a verification
It creates a transaction for that customer, saying what to verify — document and selfie, document only, or selfie only — and what counts as acceptable: which documents from which countries, how strict the face match should be, what to do about a rooted phone, how long the person has to finish. Every rule is optional and has a sensible default.The response includes an
sdk_token. It is the only thing your app needs, and it can only act on this one transaction.4
Your app runs the capture
Your app receives the
sdk_token from your backend and hands it to the chmod SDK. The SDK takes over the screen: a welcome step, the document photos, the liveness selfie, and a result screen. Then it hands control back with one of three outcomes: completed, cancelled or failed.5
chmod analyses
Usually within seconds of the capture ending, chmod reads the document, checks it for tampering, confirms a real person was present, compares the faces, evaluates the device, and matches the extracted data against what you asked for. Every applicable check runs to completion, so you get all the findings at once.
6
Your backend receives the decision
chmod calls your webhook to say the transaction has a result. Your backend fetches the transaction and reads the decision — approved, rejected, or undetermined when the analysis could not run — together with a stable code for every finding. You update your user, and the round trip is over.
What you will have built
- One endpoint on your backend that your app calls to start a verification. It authenticates your user, creates the transaction, and returns only the
sdk_token. - A screen in your app that calls that endpoint and launches the SDK.
- A webhook endpoint that verifies chmod’s signature, fetches the transaction, and acts on the decision.
Next
API quickstart
The same flow as five requests you can run today.
How verification works
The transaction lifecycle and the decision rules.
What you can configure
The rules you can enforce, explained.
Client SDK
iOS and Android integration.

