Loading

Identity and Age Checks

Identity and age checks are performed by an external provider against a government-issued document, usually with a photograph of the holder.

Where to find it

Architect Panel → Security:

  • User Verification — the console — providers, types, checks and their history

How it runs

The user is sent to the provider, photographs their document and usually themselves, and the provider compares the two and validates the document. The platform receives an outcome, a short evidence summary and the provider's reference.

The documents do not come here

The image of the passport stays with the provider. What is recorded on your side is the conclusion.

This is the right division. Holding identity documents is a serious responsibility — storage, retention, disclosure, breach exposure — and the provider is built and contracted for it. Keeping only the outcome means a breach of your database does not expose anybody's passport.

Age is a smaller ask than identity

They use the same kind of document, but they establish different things and should not be treated as interchangeable.

An age check answers whether somebody is over a threshold. An identity check establishes who they are and returns a name you then hold. If your obligation is age-related, ask for age — requesting full identity verification collects more than you need, and the extra is data you must then justify holding.

Expect some people to fail legitimately

Document checks do not succeed for everybody. Worn documents, poor cameras, poor lighting, some disabilities, and people without a passport or driving licence all produce failures that are nothing to do with fraud.

Plan an alternative route — manual review, an affiliation check, a supported process — before you make a document check the only way through. A service that cannot be used by somebody with no passport has an accessibility problem, not just a verification one.

Set expectations before the redirect

Tell users what they will need and roughly how long it takes, before sending them to the provider. Someone who starts a document check on a train without their passport will abandon it and may not come back.

Cost per check

Document verification is charged per attempt, usually including failures. That is a reason to check only when you need to, to avoid re-running unnecessarily, and to keep validity periods sensible rather than short.

Read the evidence summary

When a result is queried, the summary is what tells you what the provider actually concluded. Combined with the event history — every status transition, with its source and time — it usually answers the question without contacting the provider at all.

Worked example

An age-restricted service uses an age check rather than identity verification, because its obligation is about age alone. Most users pass in a minute. Those who fail twice are offered a supported route with manual review, so no one is excluded by a camera or a worn document — and the service never holds anybody's name from a passport.

Recommendations

  • Ask for age when age is the question.
  • Always provide an alternative route.
  • Set expectations before the redirect.
  • Let the provider hold the documents.