faceping.aifaceping.aidocs

Gate devices and the SDK

Run face check-in at the door — offline, 1:1 against the scanned ticket, with liveness checks.

Gates run the FacePing SDK. Each device holds an encrypted copy of one event's face templates and checks guests on the device itself: no network needed at the door, and no face data leaves the device.

1. Give each gate a device token#

Never put an API key on a gate device. Create a device token instead — read-only, for one event, and it expires with the event's retention. In Dashboard → event → Gate devices, or:

POST /v1/events/{eventId}/device-tokens →

Lost a device? Revoke its token: it wipes its copy at its next sync.

DELETE /v1/events/{eventId}/device-tokens/{tokenId} →

2. Add the SDK (.NET MAUI)#

The MAUI SDK runs on Android 7.0+ and iOS 15+. Native Swift, Kotlin, Flutter and React Native SDKs follow the same design.

// MauiProgram.cs
builder.UseFacePing(o => o.ApiBaseUrl = new("https://api-eu.faceping.ai/"));

3. Sync, then check guests#

var gate = await gateFactory.CreateAsync(eventId, deviceToken); // FacePingGateFactory, injected
await gate.SyncAsync();                                          // auto-sync then runs every 5 minutes
using var session = await gate.OpenAsync();                      // works offline from here

// For each guest: scan the ticket, then feed live camera frames.
var attempt = session!.BeginAttempt(scannedTicket);
var orienter = new FrameOrienter(await models.PipelineAsync());   // FacePingModels, injected; frames arrive sideways
while (attempt.State == GateAttemptState.Pending)
{
    ShowPrompt(attempt.Prompt);                                  // LookAtCamera / TurnLeft / TurnRight / LookBack
    attempt.Feed(orienter.Upright(MauiFrames.FromPlatformImage(frame)!));
}
Result What to do
Admitted Open the gate
NotEnrolled, LeaseExpired, Closed, Expired Standard (non-face) lane
LivenessFailed, ChallengeFailed, NoMatch, NoFace Staffed lane

Anti-spoofing#

BeginAttempt applies FacePing's gate policy for you:

  • Passive liveness on every frame (score ≥ 0.9) — one frame that looks like a photo or screen ends the attempt.
  • Active liveness: after a live frontal match, the guest turns their head in a random direction, then looks back for a second match. Any wrong-way turn fails.
  • 10-second window, then the staffed lane.

These defeat photos and screens. A replayed video of the guest could beat the head turn; for unattended gates, run face lanes with staff in view.

Offline and withdrawal#

  • Packs are AES-256-GCM encrypted with a per-event key held in the device keychain/keystore.
  • A device that can't reach FacePing keeps working for 24 hours (its lease), then stops verifying until it syncs.
  • Revoking a device, deleting the event or suspending your account wipes devices at their next sync.
  • At the retention deadline the device deletes the key first, then the data — even offline.