faceping.aidocs

Devices and offline sync

Run face check-in on your own devices: offline, 1:1 against the scanned ID, with liveness checks.

Check-in devices (phones, tablets, kiosks or gates) run the FacePing SDK. Each device holds an encrypted copy of one check-in list's face templates and checks people on the device itself: no network needed at the point of check-in, and no face data leaves the device.

1. Add each device to the list#

Never put an API key on a check-in device. Add the device to a list instead: you get a device token (token, starting fpd_) that is read-only, for that one list. For a list with an end date it expires with the list's retention; for an ongoing list it lasts until you revoke it or delete the list (expiresAt is null). The token is shown only once. Add a device in Dashboard → Lists → your list → Devices, or:

POST /v1/lists/{listId}/devices →

See a list's devices and when each last synced (lastSyncAt):

GET /v1/lists/{listId}/devices →

Lost a device? Revoke it (with the id from addDevice or listDevices): it wipes its copy at its next sync.

DELETE /v1/lists/{listId}/devices/{deviceId} →

2. Add the SDK (.NET MAUI)#

The SDKs run on Android 7.0+ and iOS 15+: .NET MAUI, iOS (Swift) (iOS 15.1+), Android (Kotlin), Flutter and React Native (iOS 15.1+ for both).

// MauiProgram.cs
builder.UseFacePing(o =>
{
    o.DeviceToken = "fpd_…";                                  // this device's token
    o.Region = FacePingRegion.EU;                             // your account's region
});

3. Sync, then check people in#

The SDK syncs when the app starts and then every 5 minutes. Call SyncAsync yourself to sync now.

await faceping.SyncAsync();                                    // IFacePing, injected; works offline from here

// For each person: scan their ID (ticket, membership card or badge), then run a live check on the camera.
var result = await faceping.VerifyLiveAsync(scannedId, Camera);   // Camera: a FaceCameraView, which shows the prompts
Result What to do
Match Verified: let them in, open the turnstile or record the check-in
NotEnrolled, LeaseExpired, Expired Use your standard (non-face) check-in
LivenessFailed, ChallengeFailed, NoMatch, NoFace Hand over to a member of staff

Anti-spoofing#

VerifyLiveAsync applies FacePing's check-in policy for you:

  • Passive liveness on every frame (score ≥ 0.9): one frame that looks like a photo or screen ends the attempt.
  • Active liveness: after a live frontal match, the person turns their head in a random direction, then looks back for a second match. Any wrong-way turn fails.
  • 10-second window, then hand over to staff.

These defeat photos and screens. A replayed video of the person could beat the head turn; for unattended devices, keep staff in view.

Offline and withdrawal#

  • Packs are AES-256-GCM encrypted with a per-list key held in the device keychain/keystore.
  • A device that can't reach FacePing keeps working for 24 hours (its lease), then stops verifying until it syncs.
  • Revoking a device, deleting the list or suspending your account wipes devices at their next sync.
  • At the retention deadline the device deletes the key first, then the data, even offline.
  • On an ongoing list, each sync leaves out anyone due for deletion within the next 24 hours, so a device drops a face up to a day before its maximum age and never keeps it past. A device that can't sync for 30 days wipes everything.