Server-side enrolment
Enrol guests from your own app or kiosk when you collect the photo and consent yourself.
Use this when the guest opts in inside your app (for example a native app or a staffed box office). If you can, prefer the widget: it handles consent wording, the camera and photo quality for you, and keeps photos off your servers.
The request#
POST /v1/events/{eventId}/enrolments →
{
"ticketId": "ACME-000123",
"imageBase64": "<JPEG, base64>",
"consent": {
"consentTextVersion": "uk-v1",
"givenAt": "2026-11-01T14:03:00Z",
"explicitBiometricConsent": true,
"writtenRelease": true,
"subjectUnder16": false,
"guardianConsent": false
}
}
FacePing checks the consent before it even decodes the photo: without explicit consent and the written release (and a guardian's consent for under-16s), it refuses with 400 and never processes the image.
Consent#
Record exactly what the guest agreed to. Use the published wording for your region and send its version:
| Region | Version | Wording |
|---|---|---|
| UK | uk-v1 |
Consent wording |
| EU | eu-v1 |
Consent wording |
| US | us-v1 |
Written biometric release (wording) |
If you change the wording, give it a new version id. Guests must tick the boxes themselves: never pre-tick them, and never make face check-in a condition of buying a ticket.
The photo#
- One face, looking at the camera, in good light; nothing covering it.
- JPEG, longest side up to about 1280 px — larger photos work but upload slowly, and FacePing works at 1280 px anyway. (The SDK's
EnrolmentPhoto.Preparedoes this for you.) - Up to 15 MB.
| Response | Meaning |
|---|---|
200 |
Enrolled. Re-enrolling the same ticket replaces it (not billed again). |
400 |
Consent missing or invalid, or the image isn't valid base64/JPEG/PNG. |
402 |
Your plan doesn't allow more guests (pilot limit, or no plan). |
409 |
Enrolment is closed for this event, or it has ended. |
422 |
No usable face: none found, more than one, or too small. Ask for a new photo. |
The photo is used once and never stored or logged.