Skip to main content

Biometric verification (v1)

Stable / GA

This is the current stable version of this step type. A successor version of this step is currently in preview / alpha: Biometric verification (v1)

Authenticates identity using facial recognition​

Used when strong, real‑time identity confirmation is required. The user completes a quick face scan, and the system ensures they are a real person and match the enrolled face, helping prevent impersonation, spoofing, and deepfakes.


Key features​

  • Liveness detection: Confirms the user is physically present and not a spoof or replay attack.
  • Face comparison: Matches the live capture against the enrolled biometric template.
  • Evidence preservation: On success, the authentication result is recorded in the AuthenticationResult data block for audit purposes.

This step requires previous enrolment via the Biometric enrolment (v1) step and uses the captured biometric data to authenticate the user.


Configuration​

OptionTypeRequiredDefaultDescription
providerstringNo—Biometric verification provider. Currently KEYLESS is the only supported value and is used regardless of this field. Accepted values: KEYLESS.
enableRetrybooleanNofalseWhen true, adds a retry output route that can be used to handle user cancellations.

Example configuration​

{
"enableRetry": true
}

Input data blocks​

Data blockRequiredDescription
UserReferenceYesContains the unique subject identifier (subjectId) necessary to identify the user in the Keyless system.
Reuse of existing subjectId

For the Biometric Authentication to be successful, the same subjectId that was used for Biometric Enrolment needs to be used.


Routes​

RouteDescription
authenticatedBiometric authentication succeeded. The user has been successfully authenticated.
failedBiometric authentication failed. This can be due to biometric mismatch, capture error, or technical issue.
retryAvailable only when enableRetry is true. User cancelled and can retry.

Output data blocks​

RouteData blocks produced
authenticatedAuthenticationResult
failedAuthenticationResult
retryAuthenticationResult
Available only when enableRetry is true.

Example payloads​

AuthenticationResult datablock is deprecated

AuthenticationResult is deprecated. Use Biometric verification (v2) for new flows — it produces the unified Verification data block instead.

AuthenticationResult — success
{
"result": "success",
"provider": "keyless",
"credentialId": "cred-7f3a2b1c-4e5d-4a6f-9c8b-0d1e2f3a4b5c",
"credentialType": "FACE",
"subjectId": "usr-a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"requestId": "req-b2d4f6a8-c1e3-4d5f-8a9b-0c2e4f6a8b0d",
"authenticatedAt": "2026-02-10T14:00:01.000Z"
}
AuthenticationResult datablock is deprecated

AuthenticationResult is deprecated. Use Biometric verification (v2) for new flows — it produces the unified Verification data block instead.

AuthenticationResult — failure
{
"result": "failure",
"provider": "keyless",
"credentialId": "cred-7f3a2b1c-4e5d-4a6f-9c8b-0d1e2f3a4b5c",
"credentialType": "FACE",
"subjectId": "usr-a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"requestId": "req-d4f6a8b0-c2e4-4f6a-8b0d-c2e4f6a8b0d2",
"attemptedAt": "2026-02-10T14:01:30.000Z",
"reason": {
"code": "BIOMETRIC_MISMATCH",
"details": null
}
}