Process a FaceTec SDK capture
Forwards one FaceTec SDK v10 capture (requestBlob) of a
method: facetec_sdk verification to DracmaTrust and returns the
responseBlob that the SDK expects in proceedToNextStep. Call it
once per camera capture, from your backend (the SDK session token
and the requestBlob travel app → your backend → CorpX).
Content-Type: application/jsonis mandatory. The body is limited to 5 MB (413 payload_too_large); a typicalrequestBlobis 1–3 MB.processed: falsemeans the SDK asked for a retake (face not centered, bad light…). It does not count as an attempt. Pass theresponseBlobto the SDK and let it retry.processed: truewith a failed liveness or face match counts one attempt. After 3 failed attempts the verification becomesFAILED(liveness_failedorface_mismatch). Independently, the 16th call for the same verification is rejected with429 facetec_attempts_exhaustedand the verification fails.- Calls for the same verification are serialized by a 15-second
lease: a concurrent call gets
409 facetec_process_in_progress. - If the session token expired (10 minutes), the provider answers
409 facetec_session_expired: request a new token at/facetec/sessionand capture again (no attempt consumed). - For
referenceMatch: image, sendreferenceImage(base64 JPEG/PNG of the reference face, up to 2 MB, never a document photo) in every call.
The final status (APPROVED / FAILED) is owned by the
workflow and arrives in GET /v1/identity-verifications/{id} and in
the identity.verification.completed webhook within seconds.
checks in this response already shows the per-capability result of
this capture.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Path parameters
Headers
Value of FaceTecSDK.createFaceTecAPIUserAgentString(sessionId) from the SDK. Recommended; forwarded to the provider.
Optional client-generated idempotency token (recommended for safe retries).
Unix seconds. Required on the signed host; tolerance is 300s either way (403 request_timestamp_skew).
Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns 400 body_hash_mismatch.
Detached JWS (<protected>..<signature>, ES256 or PS256) over METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256.
Request
Opaque requestBlob produced by the FaceTec SDK v10 for this capture. Typically 1–3 MB.
Base64 JPEG/PNG of the reference face (a selfie or portrait),
up to 2 MB decoded. Required when referenceMatch is image;
rejected otherwise (400 invalid_payload). Never send a photo of
an identity document: the match would only prove that the live
person looks like the document photo, not that the document
belongs to them, and the provider rejects documents it detects.
The image is forwarded to the provider and not stored by CorpX.
Above 2 MB → 413 payload_too_large with
details.field = referenceImage.
Response
Capture forwarded. Always pass responseBlob to the SDK.
Opaque blob to pass to the SDK (proceedToNextStep). Always present on 200.
false = the SDK asked for a retake (no attempt consumed). true = the capture was evaluated; see checks.
Per-capability result, read separately from the aggregate status.
faceMatch.result is not_performed when referenceMatch is none:
an APPROVED in that mode only proves liveness.
Present once the verification is FAILED.