Face match, ID reading and a face fingerprint to dedupe your own users, over one REST API.
$ curl https://api.firstpass.cloud/v1/kyc/session \ -H "Authorization: Bearer $KEY" \ -H "Content-Type: application/json" \ -d '{"level": "A"}' { "session_id": "…", "url": "https://firstpass.cloud/kyc.html?session=…", "status": "pending" } # send the applicant there: live face scan; selfie uploads are disabled. Then poll: $ curl https://api.firstpass.cloud/v1/kyc/session/SESSION_ID \ -H "Authorization: Bearer $KEY" { "status": "done", "result": { "outcome": "verified", "face_match": { "verdict": "match", "similarity": 0.67 }, "document": { "doc_type": "パスポート", "expiry_date": "2031-05-14" }, "face_embedding": […128-d fingerprint, store it to dedupe your own users…] } }
Level A is the standard check: a live face scan, an ID document and basic details. Level B adds proof of residence and source of funds. The demo runs face match and document reading and shows the face verdict here. It does not validate your name, email or phone or run Level B cross-checks; its face scan is only checked in your browser. The hosted check your signups use adds server-side liveness and returns verified, review or rejected; your own team decides the review cases. The demo keeps no photos, only your email, IP address and the result.
Face match and ID reading demo. No account needed.
Public list prices for entry plans, August 2026. Most providers also charge a monthly minimum whether you verify anyone or not.
Sources: sumsub.com/pricing, beverified.org, hyperverge.co. Check current prices before you decide.
Brokers verify everyone at registration, but most accounts never deposit. Paying certified-KYC prices on all of them is the single biggest waste in your onboarding bill. Route every signup through FirstPass first, and send only the accounts that fund to your certified provider.
Recommended: open a hosted session and send your user to the scan page. We run the live face scan (forced, no photo upload), read the ID and, for Level B, the residence and funds documents, then store the record. Liveness only runs in hosted sessions. Pick Level A or Level B per user. Copy the code:
curl -X POST https://api.firstpass.cloud/v1/kyc/session \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"level": "A", "applicant_ref": "user_123", "lang": "en"}'
curl -X POST https://api.firstpass.cloud/v1/kyc/session \
-H "Authorization: Bearer $KEY" \
-H "Content-Type: application/json" \
-d '{"level": "B", "applicant_ref": "user_123", "lang": "en"}'
curl https://api.firstpass.cloud/v1/kyc/session/SESSION_ID \ -H "Authorization: Bearer $KEY"
Live face scan, ID document reading and name / email / phone checks, plus a 128-d face fingerprint you can store to catch one person opening many accounts on your platform. We run no face search ourselves and never match faces across customers. 1 credit ($0.10) per billable session: the pass every signup goes through.
Everything in Level A, plus proof-of-residence and source-of-funds document reading, birth date and address cross-checks (the hosted B page requires all declared fields; direct API fields are optional), and declared occupation, PEP status, source and annual income (recorded, not verified). 2 credits ($0.20).
Composing your own flow instead? Call POST /v1/kyc/a (1 credit) or /v1/kyc/b (2 credits) with base64 images directly. These direct calls run no liveness check. The granular endpoints /v1/face/compare, /v1/face/embed, /v1/document/ocr, /v1/document/por and /v1/identity/basic cost 1 credit each.
Run the cheap level on everyone at registration; run the full level when a user funds, withdraws, or crosses your risk threshold. You compose levels from the same API calls, so the split is entirely your policy.
Create a hosted session for face match, ID reading and basic detail checks, then poll for the result. The standard pass every signup goes through.
Everything in Level A, plus proof-of-residence and source-of-funds documents, cross-checks of birth date against the ID and address against the proof of residence, and declared nationality, occupation, PEP status, source and annual income. Meant for accounts that fund or withdraw. The hosted B page requires both proofs and all declared fields; direct API fields are optional. Cross-checks run when the relevant data is available, the declared fields are recorded but not verified, and there is no sanctions or PEP screening.
Your team signs into the portal with email and password (API key login also works): monthly usage and cost, verdict breakdown, cases flagged for human review, and a quickstart for the next developer. The screenshot below shows the dashboard.
We would rather lose a deal than blur this. FirstPass is a pre-screening tool that makes your human review fast and your certified-KYC bill small. It does not replace either.
Create a workspace, top up by card, and route today's signups through FirstPass. Your API key is shown after registration.
Instant workspace. The key appears here. We also attempt to send it by email; save the copy shown here. Sign in to the dashboard with your email and this password.
This key is shown once, save it now. Sign in to the dashboard with your email and password to top up by card; API key login also works.
Next: open the dashboard. Save your key now.