Devices and offline sync
Run face check-in on your own devices: offline, 1:1 against the scanned ID, with liveness checks.
Check-in devices (phones, tablets, kiosks or gates) run the FacePing SDK. Each device holds an encrypted copy of one check-in list's face templates and checks people on the device itself: no network needed at the point of check-in, and no face data leaves the device.
1. Add each device to the list#
Never put an API key on a check-in device. Add the device to a list instead: you get a device token (token, starting fpd_) that is read-only, for that one list. For a list with an end date it expires with the list's retention; for an ongoing list it lasts until you revoke it or delete the list (expiresAt is null). The token is shown only once. Add a device in Dashboard → Lists → your list → Devices, or:
POST /v1/lists/{listId}/devices →
See a list's devices and when each last synced (lastSyncAt):
GET /v1/lists/{listId}/devices →
Lost a device? Revoke it (with the id from addDevice or listDevices): it wipes its copy at its next sync.
DELETE /v1/lists/{listId}/devices/{deviceId} →
2. Add the SDK (.NET MAUI)#
The SDKs run on Android 7.0+ and iOS 15+: .NET MAUI, iOS (Swift) (iOS 15.1+), Android (Kotlin), Flutter and React Native (iOS 15.1+ for both).
// MauiProgram.cs
builder.UseFacePing(o =>
{
o.DeviceToken = "fpd_…"; // this device's token
o.Region = FacePingRegion.EU; // your account's region
});
3. Sync, then check people in#
The SDK syncs when the app starts and then every 5 minutes. Call SyncAsync yourself to sync now.
await faceping.SyncAsync(); // IFacePing, injected; works offline from here
// For each person: scan their ID (ticket, membership card or badge), then run a live check on the camera.
var result = await faceping.VerifyLiveAsync(scannedId, Camera); // Camera: a FaceCameraView, which shows the prompts
| Result | What to do |
|---|---|
Match |
Verified: let them in, open the turnstile or record the check-in |
NotEnrolled, LeaseExpired, Expired |
Use your standard (non-face) check-in |
LivenessFailed, ChallengeFailed, NoMatch, NoFace |
Hand over to a member of staff |
Anti-spoofing#
VerifyLiveAsync applies FacePing's check-in policy for you:
- Passive liveness on every frame (score ≥ 0.9): one frame that looks like a photo or screen ends the attempt.
- Active liveness: after a live frontal match, the person turns their head in a random direction, then looks back for a second match. Any wrong-way turn fails.
- 10-second window, then hand over to staff.
These defeat photos and screens. A replayed video of the person could beat the head turn; for unattended devices, keep staff in view.
Offline and withdrawal#
- Packs are AES-256-GCM encrypted with a per-list key held in the device keychain/keystore.
- A device that can't reach FacePing keeps working for 24 hours (its lease), then stops verifying until it syncs.
- Revoking a device, deleting the list or suspending your account wipes devices at their next sync.
- At the retention deadline the device deletes the key first, then the data, even offline.
- On an ongoing list, each sync leaves out anyone due for deletion within the next 24 hours, so a device drops a face up to a day before its maximum age and never keeps it past. A device that can't sync for 30 days wipes everything.