Skip to main content
A verification is one round trip between your backend, your app and chmod. This page walks through it once, in order, so the pieces make sense before you touch an endpoint. The requests themselves are in the API Reference quickstart.
1

Your backend identifies itself

Your server exchanges its client credentials for a short-lived access token. That token authenticates every call your backend makes to chmod for the next hour. It never leaves your server.
2

Your backend registers the person

It creates a customer: chmod’s persistent record of one person. You get back a customer_id, and you store it against your own user — once, forever. Every later verification of the same person reuses it, which is what lets chmod compare a new selfie against the face it enrolled the first time and notice when a document contradicts an earlier one.
3

Your backend opens a verification

It creates a transaction for that customer, saying what to verify — document and selfie, document only, or selfie only — and what counts as acceptable: which documents from which countries, how strict the face match should be, what to do about a rooted phone, how long the person has to finish. Every rule is optional and has a sensible default.The response includes an sdk_token. It is the only thing your app needs, and it can only act on this one transaction.
4

Your app runs the capture

Your app receives the sdk_token from your backend and hands it to the chmod SDK. The SDK takes over the screen: a welcome step, the document photos, the liveness selfie, and a result screen. Then it hands control back with one of three outcomes: completed, cancelled or failed.
Completed means the person finished the flow — not that they were approved. Show something like “we’re reviewing your document” and move on. The verdict comes next, and it arrives on your backend.
5

chmod analyses

Usually within seconds of the capture ending, chmod reads the document, checks it for tampering, confirms a real person was present, compares the faces, evaluates the device, and matches the extracted data against what you asked for. Every applicable check runs to completion, so you get all the findings at once.
6

Your backend receives the decision

chmod calls your webhook to say the transaction has a result. Your backend fetches the transaction and reads the decision — approved, rejected, or undetermined when the analysis could not run — together with a stable code for every finding. You update your user, and the round trip is over.

What you will have built

  • One endpoint on your backend that your app calls to start a verification. It authenticates your user, creates the transaction, and returns only the sdk_token.
  • A screen in your app that calls that endpoint and launches the SDK.
  • A webhook endpoint that verifies chmod’s signature, fetches the transaction, and acts on the decision.
Three pieces, none of them large.

Next

API quickstart

The same flow as five requests you can run today.

How verification works

The transaction lifecycle and the decision rules.

What you can configure

The rules you can enforce, explained.

Client SDK

iOS and Android integration.