> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://en.docs.api.corpx.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://en.docs.api.corpx.com/_mcp/server.

# Process a FaceTec SDK capture

POST https://client.api.corpx.com/v1/identity-verifications/{verificationId}/facetec/process
Content-Type: application/json

Forwards one FaceTec SDK v10 capture (`requestBlob`) of a
`method: facetec_sdk` verification to DracmaTrust and returns the
`responseBlob` that the SDK expects in `proceedToNextStep`. Call it
**once per camera capture**, from your backend (the SDK session token
and the `requestBlob` travel app → your backend → CorpX).

* `Content-Type: application/json` is mandatory. The body is limited
  to **5 MB** (`413 payload_too_large`); a typical `requestBlob` is
  1–3 MB.
* `processed: false` means the SDK asked for a retake (face not
  centered, bad light…). It does **not** count as an attempt. Pass
  the `responseBlob` to the SDK and let it retry.
* `processed: true` with a failed liveness or face match counts one
  attempt. After **3 failed attempts** the verification becomes
  `FAILED` (`liveness_failed` or `face_mismatch`). Independently,
  the **16th call** for the same verification is rejected with
  `429 facetec_attempts_exhausted` and the verification fails.
* Calls for the same verification are serialized by a 15-second
  lease: a concurrent call gets `409 facetec_process_in_progress`.
* If the session token expired (10 minutes), the provider answers
  `409 facetec_session_expired`: request a new token at
  `/facetec/session` and capture again (no attempt consumed).
* For `referenceMatch: image`, send `referenceImage` (base64
  JPEG/PNG of the reference face, up to 2 MB, never a document
  photo) in every call.

The final `status` (`APPROVED` / `FAILED`) is owned by the
workflow and arrives in `GET /v1/identity-verifications/{id}` and in
the `identity.verification.completed` webhook within seconds.
`checks` in this response already shows the per-capability result of
this capture.

Reference: https://en.docs.api.corpx.com/ib/referencia/identity-verification/process-identity-verification-face-tec

## Authentication

- `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer <token>`, where token is your auth token.

## Request

### Path parameters

- `verificationId` (string, required) — Standalone identity verification identifier returned by the creation endpoint.

### Headers

- `X-Tenant-Id` (string, required) — Tenant context used for authorization and routing.
- `X-FaceTec-User-Agent` (string, optional) — Value of `FaceTecSDK.createFaceTecAPIUserAgentString(sessionId)` from the SDK. Recommended; forwarded to the provider.
- `Idempotency-Key` (string, optional) — Optional client-generated idempotency token (recommended for safe retries).
- `X-Request-Timestamp` (string, required) — Unix seconds. Required on the signed host; tolerance is 300s either way (`403 request_timestamp_skew`).
- `X-Content-SHA256` (string, required) — Lowercase hex SHA-256 of the body. An empty body hashes the empty string, so the header is always present. Mismatch returns `400 body_hash_mismatch`.
- `X-Request-Signature` (string, required) — Detached JWS (`<protected>..<signature>`, ES256 or PS256) over `METHOD\nPATH?QUERY\nTIMESTAMP\nIDEMPOTENCY_KEY_OR_EMPTY\nX_CONTENT_SHA256`.

### Body (application/json)

This endpoint expects an IdentityVerificationFaceTecProcessRequest.

- `requestBlob` (string, required) — Opaque `requestBlob` produced by the FaceTec SDK v10 for this capture. Typically 1–3 MB.
- `sessionId` (string, required) — FaceTec session id reported by the SDK for this capture.
- `referenceImage` (string, optional) — Base64 JPEG/PNG of the reference **face** (a selfie or portrait), up to 2 MB decoded. Required when `referenceMatch` is `image`; rejected otherwise (`400 invalid_payload`). Never send a photo of an identity document: the match would only prove that the live person looks like the document photo, not that the document belongs to them, and the provider rejects documents it detects. The image is forwarded to the provider and not stored by CorpX. Above 2 MB → `413 payload_too_large` with `details.field = referenceImage`.

## Response

### 200

Capture forwarded. Always pass `responseBlob` to the SDK.

- `verificationId` (string, required)
- `responseBlob` (string, required) — Opaque blob to pass to the SDK (`proceedToNextStep`). Always present on 200.
- `processed` (boolean, required) — `false` = the SDK asked for a retake (no attempt consumed). `true` = the capture was evaluated; see `checks`.
- `status` (enum, required) — Current state of the standalone verification.
  - Allowed values: `PENDING`, `APPROVED`, `FAILED`, `EXPIRED`
- `attemptsRemaining` (integer, required) — Failed captures still allowed after this call.
- `checks` (IdentityVerificationChecks, required) — Per-capability result, read separately from the aggregate `status`. `faceMatch.result` is `not_performed` when `referenceMatch` is `none`: an `APPROVED` in that mode only proves liveness.
- `failureReason` (enum, optional) — Present once the verification is `FAILED`.
  - Allowed values: `liveness_failed`, `face_mismatch`, `provider_error`

## Errors

### 400 Bad Request Error

`invalid_payload` (missing `requestBlob`/`sessionId`) or `reference_image_required` (`referenceMatch: image` without `referenceImage`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 401 Unauthorized Error

Authentication failed or token missing.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 403 Forbidden Error

Insufficient scope or caller is not the master M2M credential.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 404 Not Found Error

Verification not found in this tenant (`verification_not_found`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 409 Conflict Error

`verification_method_mismatch` (not a `facetec_sdk` verification), `verification_not_pending`, `facetec_process_in_progress` (another capture is being processed; `Retry-After: 2`) or `facetec_session_expired` (renew at `/facetec/session`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 413 Content Too Large Error

Body larger than the limit (`payload_too_large`, `details.maxBytes`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 415 Unsupported Media Type Error

`Content-Type` is not `application/json` (`unsupported_media_type`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 429 Too Many Requests Error

`facetec_attempts_exhausted` — no attempts left (3 failed, or 15 total calls). The verification is `FAILED`; create a new one.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 500 Internal Server Error

Unexpected server error.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 502 Bad Gateway Error

The provider returned an error (`provider_error`); `partner` carries the raw detail. Capture again; no attempt consumed.

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

### 503 Service Unavailable Error

Provider unavailable (`provider_unavailable`, `facetec_unavailable`).

- `errorCode` (string, required) — Stable machine-readable code. See `ErrorCode` for the known values.
- `message` (string, required) — Human-readable explanation (pt-BR). Presentation only; may change.
- `docs` (string, optional) — Link to this code in the public error catalogue.
- `requestId` (string, optional) — Gateway request id. Quote it when contacting support.
- `details` (map from string to any, optional) — Optional machine-readable context for the specific `errorCode` (for example `kind` on `identity_verification_monthly_limit_exceeded`, `maxBytes` on `payload_too_large`, `attemptsRemaining` on `facetec_attempts_exhausted`). Keys are documented per operation; absent when the code carries no extra context.
- `partner` (ErrorResponsePartner, optional) — Raw error from the settlement bank, when the failure came from it. Diagnostic only.

## Types

### IdentityVerificationChecks

Per-capability result, read separately from the aggregate `status`. `faceMatch.result` is `not_performed` when `referenceMatch` is `none`: an `APPROVED` in that mode only proves liveness.

- `liveness` (enum, required) — 3D liveness (presentation-attack detection) result.
  - Allowed values: `pending`, `passed`, `failed`
- `faceMatch` (IdentityVerificationChecksFaceMatch, required)

### ErrorResponsePartner

Raw error from the settlement bank, when the failure came from it. Diagnostic only.

- `code` (string, optional)
- `message` (string, optional)
- `field` (string, optional) — Field the partner pointed at, when any.

### IdentityVerificationChecksFaceMatch

- `result` (enum, required) — 1:1 face match result against the chosen reference.
  - Allowed values: `pending`, `passed`, `failed`, `not_performed`
- `reference` (enum, optional) — Reference used. Omitted when `result` is `not_performed`.
  - Allowed values: `dracma`, `image`

## Examples

### SDK asked for a retake (no attempt consumed)

**Response**

```json
{
  "verificationId": "idv_01J8Y7C8D9E0F1G2H3J4",
  "responseBlob": "eyJ...base64-opaque-from-provider...",
  "processed": false,
  "status": "PENDING",
  "attemptsRemaining": 3,
  "checks": {
    "liveness": "pending",
    "faceMatch": {
      "result": "pending",
      "reference": "dracma"
    }
  }
}
```

**SDK Code**

```python SDK asked for a retake (no attempt consumed)
import requests

url = "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

headers = {
    "X-Content-SHA256": "X-Content-SHA256",
    "X-Request-Signature": "X-Request-Signature",
    "X-Request-Timestamp": "X-Request-Timestamp",
    "X-Tenant-Id": "X-Tenant-Id",
    "Authorization": "Bearer <token>"
}

response = requests.post(url, headers=headers)

print(response.json())
```

```javascript SDK asked for a retake (no attempt consumed)
const url = 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process';
const options = {
  method: 'POST',
  headers: {
    'X-Content-SHA256': 'X-Content-SHA256',
    'X-Request-Signature': 'X-Request-Signature',
    'X-Request-Timestamp': 'X-Request-Timestamp',
    'X-Tenant-Id': 'X-Tenant-Id',
    Authorization: 'Bearer <token>'
  }
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go SDK asked for a retake (no attempt consumed)
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("X-Content-SHA256", "X-Content-SHA256")
	req.Header.Add("X-Request-Signature", "X-Request-Signature")
	req.Header.Add("X-Request-Timestamp", "X-Request-Timestamp")
	req.Header.Add("X-Tenant-Id", "X-Tenant-Id")
	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby SDK asked for a retake (no attempt consumed)
require 'uri'
require 'net/http'

url = URI("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["X-Content-SHA256"] = 'X-Content-SHA256'
request["X-Request-Signature"] = 'X-Request-Signature'
request["X-Request-Timestamp"] = 'X-Request-Timestamp'
request["X-Tenant-Id"] = 'X-Tenant-Id'
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java SDK asked for a retake (no attempt consumed)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")
  .header("X-Content-SHA256", "X-Content-SHA256")
  .header("X-Request-Signature", "X-Request-Signature")
  .header("X-Request-Timestamp", "X-Request-Timestamp")
  .header("X-Tenant-Id", "X-Tenant-Id")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php SDK asked for a retake (no attempt consumed)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'X-Content-SHA256' => 'X-Content-SHA256',
    'X-Request-Signature' => 'X-Request-Signature',
    'X-Request-Timestamp' => 'X-Request-Timestamp',
    'X-Tenant-Id' => 'X-Tenant-Id',
  ],
]);

echo $response->getBody();
```

```csharp SDK asked for a retake (no attempt consumed)
using RestSharp;

var client = new RestClient("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process");
var request = new RestRequest(Method.POST);
request.AddHeader("X-Content-SHA256", "X-Content-SHA256");
request.AddHeader("X-Request-Signature", "X-Request-Signature");
request.AddHeader("X-Request-Timestamp", "X-Request-Timestamp");
request.AddHeader("X-Tenant-Id", "X-Tenant-Id");
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift SDK asked for a retake (no attempt consumed)
import Foundation

let headers = [
  "X-Content-SHA256": "X-Content-SHA256",
  "X-Request-Signature": "X-Request-Signature",
  "X-Request-Timestamp": "X-Request-Timestamp",
  "X-Tenant-Id": "X-Tenant-Id",
  "Authorization": "Bearer <token>"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Liveness and match passed

**Response**

```json
{
  "verificationId": "idv_01J8Y7C8D9E0F1G2H3J4",
  "responseBlob": "eyJ...base64-opaque-from-provider...",
  "processed": true,
  "status": "PENDING",
  "attemptsRemaining": 3,
  "checks": {
    "liveness": "passed",
    "faceMatch": {
      "result": "passed",
      "reference": "dracma"
    }
  }
}
```

**SDK Code**

```python Liveness and match passed
import requests

url = "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

headers = {
    "X-Content-SHA256": "X-Content-SHA256",
    "X-Request-Signature": "X-Request-Signature",
    "X-Request-Timestamp": "X-Request-Timestamp",
    "X-Tenant-Id": "X-Tenant-Id",
    "Authorization": "Bearer <token>"
}

response = requests.post(url, headers=headers)

print(response.json())
```

```javascript Liveness and match passed
const url = 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process';
const options = {
  method: 'POST',
  headers: {
    'X-Content-SHA256': 'X-Content-SHA256',
    'X-Request-Signature': 'X-Request-Signature',
    'X-Request-Timestamp': 'X-Request-Timestamp',
    'X-Tenant-Id': 'X-Tenant-Id',
    Authorization: 'Bearer <token>'
  }
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Liveness and match passed
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("X-Content-SHA256", "X-Content-SHA256")
	req.Header.Add("X-Request-Signature", "X-Request-Signature")
	req.Header.Add("X-Request-Timestamp", "X-Request-Timestamp")
	req.Header.Add("X-Tenant-Id", "X-Tenant-Id")
	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Liveness and match passed
require 'uri'
require 'net/http'

url = URI("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["X-Content-SHA256"] = 'X-Content-SHA256'
request["X-Request-Signature"] = 'X-Request-Signature'
request["X-Request-Timestamp"] = 'X-Request-Timestamp'
request["X-Tenant-Id"] = 'X-Tenant-Id'
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java Liveness and match passed
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")
  .header("X-Content-SHA256", "X-Content-SHA256")
  .header("X-Request-Signature", "X-Request-Signature")
  .header("X-Request-Timestamp", "X-Request-Timestamp")
  .header("X-Tenant-Id", "X-Tenant-Id")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php Liveness and match passed
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'X-Content-SHA256' => 'X-Content-SHA256',
    'X-Request-Signature' => 'X-Request-Signature',
    'X-Request-Timestamp' => 'X-Request-Timestamp',
    'X-Tenant-Id' => 'X-Tenant-Id',
  ],
]);

echo $response->getBody();
```

```csharp Liveness and match passed
using RestSharp;

var client = new RestClient("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process");
var request = new RestRequest(Method.POST);
request.AddHeader("X-Content-SHA256", "X-Content-SHA256");
request.AddHeader("X-Request-Signature", "X-Request-Signature");
request.AddHeader("X-Request-Timestamp", "X-Request-Timestamp");
request.AddHeader("X-Tenant-Id", "X-Tenant-Id");
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift Liveness and match passed
import Foundation

let headers = [
  "X-Content-SHA256": "X-Content-SHA256",
  "X-Request-Signature": "X-Request-Signature",
  "X-Request-Timestamp": "X-Request-Timestamp",
  "X-Tenant-Id": "X-Tenant-Id",
  "Authorization": "Bearer <token>"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Liveness failed (one attempt consumed)

**Response**

```json
{
  "verificationId": "idv_01J8Y7C8D9E0F1G2H3J4",
  "responseBlob": "eyJ...base64-opaque-from-provider...",
  "processed": true,
  "status": "PENDING",
  "attemptsRemaining": 2,
  "checks": {
    "liveness": "failed",
    "faceMatch": {
      "result": "pending",
      "reference": "dracma"
    }
  }
}
```

**SDK Code**

```python Liveness failed (one attempt consumed)
import requests

url = "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

headers = {
    "X-Content-SHA256": "X-Content-SHA256",
    "X-Request-Signature": "X-Request-Signature",
    "X-Request-Timestamp": "X-Request-Timestamp",
    "X-Tenant-Id": "X-Tenant-Id",
    "Authorization": "Bearer <token>"
}

response = requests.post(url, headers=headers)

print(response.json())
```

```javascript Liveness failed (one attempt consumed)
const url = 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process';
const options = {
  method: 'POST',
  headers: {
    'X-Content-SHA256': 'X-Content-SHA256',
    'X-Request-Signature': 'X-Request-Signature',
    'X-Request-Timestamp': 'X-Request-Timestamp',
    'X-Tenant-Id': 'X-Tenant-Id',
    Authorization: 'Bearer <token>'
  }
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Liveness failed (one attempt consumed)
package main

import (
	"fmt"
	"net/http"
	"io"
)

func main() {

	url := "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

	req, _ := http.NewRequest("POST", url, nil)

	req.Header.Add("X-Content-SHA256", "X-Content-SHA256")
	req.Header.Add("X-Request-Signature", "X-Request-Signature")
	req.Header.Add("X-Request-Timestamp", "X-Request-Timestamp")
	req.Header.Add("X-Tenant-Id", "X-Tenant-Id")
	req.Header.Add("Authorization", "Bearer <token>")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Liveness failed (one attempt consumed)
require 'uri'
require 'net/http'

url = URI("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["X-Content-SHA256"] = 'X-Content-SHA256'
request["X-Request-Signature"] = 'X-Request-Signature'
request["X-Request-Timestamp"] = 'X-Request-Timestamp'
request["X-Tenant-Id"] = 'X-Tenant-Id'
request["Authorization"] = 'Bearer <token>'

response = http.request(request)
puts response.read_body
```

```java Liveness failed (one attempt consumed)
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")
  .header("X-Content-SHA256", "X-Content-SHA256")
  .header("X-Request-Signature", "X-Request-Signature")
  .header("X-Request-Timestamp", "X-Request-Timestamp")
  .header("X-Tenant-Id", "X-Tenant-Id")
  .header("Authorization", "Bearer <token>")
  .asString();
```

```php Liveness failed (one attempt consumed)
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process', [
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'X-Content-SHA256' => 'X-Content-SHA256',
    'X-Request-Signature' => 'X-Request-Signature',
    'X-Request-Timestamp' => 'X-Request-Timestamp',
    'X-Tenant-Id' => 'X-Tenant-Id',
  ],
]);

echo $response->getBody();
```

```csharp Liveness failed (one attempt consumed)
using RestSharp;

var client = new RestClient("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process");
var request = new RestRequest(Method.POST);
request.AddHeader("X-Content-SHA256", "X-Content-SHA256");
request.AddHeader("X-Request-Signature", "X-Request-Signature");
request.AddHeader("X-Request-Timestamp", "X-Request-Timestamp");
request.AddHeader("X-Tenant-Id", "X-Tenant-Id");
request.AddHeader("Authorization", "Bearer <token>");
IRestResponse response = client.Execute(request);
```

```swift Liveness failed (one attempt consumed)
import Foundation

let headers = [
  "X-Content-SHA256": "X-Content-SHA256",
  "X-Request-Signature": "X-Request-Signature",
  "X-Request-Timestamp": "X-Request-Timestamp",
  "X-Tenant-Id": "X-Tenant-Id",
  "Authorization": "Bearer <token>"
]

let request = NSMutableURLRequest(url: NSURL(string: "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```

### Identity Verification_processIdentityVerificationFaceTec_example

**Request**

```json
{
  "requestBlob": "eyJ...base64-opaque-from-sdk...",
  "sessionId": "8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f"
}
```

**Response**

```json
{
  "verificationId": "idv_01J8Y7C8D9E0F1G2H3J4",
  "responseBlob": "eyJ...base64-opaque-from-provider...",
  "processed": false,
  "status": "PENDING",
  "attemptsRemaining": 3,
  "checks": {
    "liveness": "pending",
    "faceMatch": {
      "result": "pending",
      "reference": "dracma"
    }
  }
}
```

**SDK Code**

```python Identity Verification_processIdentityVerificationFaceTec_example
import requests

url = "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

payload = {
    "requestBlob": "eyJ...base64-opaque-from-sdk...",
    "sessionId": "8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f"
}
headers = {
    "X-Content-SHA256": "X-Content-SHA256",
    "X-Request-Signature": "X-Request-Signature",
    "X-Request-Timestamp": "X-Request-Timestamp",
    "X-Tenant-Id": "X-Tenant-Id",
    "Authorization": "Bearer <token>",
    "Content-Type": "application/json"
}

response = requests.post(url, json=payload, headers=headers)

print(response.json())
```

```javascript Identity Verification_processIdentityVerificationFaceTec_example
const url = 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process';
const options = {
  method: 'POST',
  headers: {
    'X-Content-SHA256': 'X-Content-SHA256',
    'X-Request-Signature': 'X-Request-Signature',
    'X-Request-Timestamp': 'X-Request-Timestamp',
    'X-Tenant-Id': 'X-Tenant-Id',
    Authorization: 'Bearer <token>',
    'Content-Type': 'application/json'
  },
  body: '{"requestBlob":"eyJ...base64-opaque-from-sdk...","sessionId":"8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f"}'
};

try {
  const response = await fetch(url, options);
  const data = await response.json();
  console.log(data);
} catch (error) {
  console.error(error);
}
```

```go Identity Verification_processIdentityVerificationFaceTec_example
package main

import (
	"fmt"
	"strings"
	"net/http"
	"io"
)

func main() {

	url := "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process"

	payload := strings.NewReader("{\n  \"requestBlob\": \"eyJ...base64-opaque-from-sdk...\",\n  \"sessionId\": \"8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f\"\n}")

	req, _ := http.NewRequest("POST", url, payload)

	req.Header.Add("X-Content-SHA256", "X-Content-SHA256")
	req.Header.Add("X-Request-Signature", "X-Request-Signature")
	req.Header.Add("X-Request-Timestamp", "X-Request-Timestamp")
	req.Header.Add("X-Tenant-Id", "X-Tenant-Id")
	req.Header.Add("Authorization", "Bearer <token>")
	req.Header.Add("Content-Type", "application/json")

	res, _ := http.DefaultClient.Do(req)

	defer res.Body.Close()
	body, _ := io.ReadAll(res.Body)

	fmt.Println(res)
	fmt.Println(string(body))

}
```

```ruby Identity Verification_processIdentityVerificationFaceTec_example
require 'uri'
require 'net/http'

url = URI("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")

http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true

request = Net::HTTP::Post.new(url)
request["X-Content-SHA256"] = 'X-Content-SHA256'
request["X-Request-Signature"] = 'X-Request-Signature'
request["X-Request-Timestamp"] = 'X-Request-Timestamp'
request["X-Tenant-Id"] = 'X-Tenant-Id'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n  \"requestBlob\": \"eyJ...base64-opaque-from-sdk...\",\n  \"sessionId\": \"8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f\"\n}"

response = http.request(request)
puts response.read_body
```

```java Identity Verification_processIdentityVerificationFaceTec_example
import com.mashape.unirest.http.HttpResponse;
import com.mashape.unirest.http.Unirest;

HttpResponse<String> response = Unirest.post("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")
  .header("X-Content-SHA256", "X-Content-SHA256")
  .header("X-Request-Signature", "X-Request-Signature")
  .header("X-Request-Timestamp", "X-Request-Timestamp")
  .header("X-Tenant-Id", "X-Tenant-Id")
  .header("Authorization", "Bearer <token>")
  .header("Content-Type", "application/json")
  .body("{\n  \"requestBlob\": \"eyJ...base64-opaque-from-sdk...\",\n  \"sessionId\": \"8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f\"\n}")
  .asString();
```

```php Identity Verification_processIdentityVerificationFaceTec_example
<?php
require_once('vendor/autoload.php');

$client = new \GuzzleHttp\Client();

$response = $client->request('POST', 'https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process', [
  'body' => '{
  "requestBlob": "eyJ...base64-opaque-from-sdk...",
  "sessionId": "8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f"
}',
  'headers' => [
    'Authorization' => 'Bearer <token>',
    'Content-Type' => 'application/json',
    'X-Content-SHA256' => 'X-Content-SHA256',
    'X-Request-Signature' => 'X-Request-Signature',
    'X-Request-Timestamp' => 'X-Request-Timestamp',
    'X-Tenant-Id' => 'X-Tenant-Id',
  ],
]);

echo $response->getBody();
```

```csharp Identity Verification_processIdentityVerificationFaceTec_example
using RestSharp;

var client = new RestClient("https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process");
var request = new RestRequest(Method.POST);
request.AddHeader("X-Content-SHA256", "X-Content-SHA256");
request.AddHeader("X-Request-Signature", "X-Request-Signature");
request.AddHeader("X-Request-Timestamp", "X-Request-Timestamp");
request.AddHeader("X-Tenant-Id", "X-Tenant-Id");
request.AddHeader("Authorization", "Bearer <token>");
request.AddHeader("Content-Type", "application/json");
request.AddParameter("application/json", "{\n  \"requestBlob\": \"eyJ...base64-opaque-from-sdk...\",\n  \"sessionId\": \"8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f\"\n}", ParameterType.RequestBody);
IRestResponse response = client.Execute(request);
```

```swift Identity Verification_processIdentityVerificationFaceTec_example
import Foundation

let headers = [
  "X-Content-SHA256": "X-Content-SHA256",
  "X-Request-Signature": "X-Request-Signature",
  "X-Request-Timestamp": "X-Request-Timestamp",
  "X-Tenant-Id": "X-Tenant-Id",
  "Authorization": "Bearer <token>",
  "Content-Type": "application/json"
]
let parameters = [
  "requestBlob": "eyJ...base64-opaque-from-sdk...",
  "sessionId": "8c2f1d2a-7e6b-4f0e-9c3d-1a2b3c4d5e6f"
] as [String : Any]

let postData = JSONSerialization.data(withJSONObject: parameters, options: [])

let request = NSMutableURLRequest(url: NSURL(string: "https://client.api.corpx.com/v1/identity-verifications/verificationId/facetec/process")! as URL,
                                        cachePolicy: .useProtocolCachePolicy,
                                    timeoutInterval: 10.0)
request.httpMethod = "POST"
request.allHTTPHeaderFields = headers
request.httpBody = postData as Data

let session = URLSession.shared
let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in
  if (error != nil) {
    print(error as Any)
  } else {
    let httpResponse = response as? HTTPURLResponse
    print(httpResponse)
  }
})

dataTask.resume()
```