faceping.aifaceping.aidocs

The enrolment widget

Let buyers opt in to face check-in on your own ticket page — two lines of HTML and one server call.

The widget is FacePing's own page (faceping.ai/enrol) shown inside your ticket page. It shows your organiser name and privacy notice, collects the guest's consent in the guest's own hands, takes the selfie and enrols them. The photo goes straight from the guest's browser to FacePing — it never reaches your servers — and is discarded once the face template is made.

Before you start#

Each event needs its widget settings — your organiser name (as guests know you) and a link to your face check-in privacy notice. FacePing won't create tokens until they're set, so no guest is ever asked to consent without a notice to read. Set them in Dashboard → event → Ticket page widget, or:

POST /v1/events/{eventId}/widget →

1. Create a token on your server#

A token lets one guest enrol for one ticket, once. Create it when you render the confirmation page (it's valid for 30 minutes):

curl -X POST https://api-eu.faceping.ai/v1/events/$EVENT_ID/enrolment-tokens \
  -H "X-Api-Key: $FACEPING_API_KEY" -H "Content-Type: application/json" \
  -d '{ "ticketId": "ACME-000123" }'

POST /v1/events/{eventId}/enrolment-tokens →

Your API key stays on your server. The token is safe to put in the page: it can only enrol that one ticket, once, and expires.

2. Embed it#

<div data-faceping-token="fpe_…"></div>
<script src="https://faceping.ai/widget.js" async></script>

The loader replaces the div with an iframe that resizes itself. To mount it yourself (for example in a single-page app, after fetching the token):

FacePing.mount(document.getElementById("face-checkin"), token);

3. Listen for the result#

The container fires DOM events you can use to update your own records:

Event When
faceping:ready The widget loaded and shows the consent step
faceping:enrolled The guest is enrolled for face check-in
faceping:declined The guest chose the standard entrance
faceping:error The token was invalid or expired (event.detail.message)
document.addEventListener("faceping:enrolled", () => markTicket("face"));
document.addEventListener("faceping:declined", () => markTicket("standard"));

What the guest sees#

  1. Consent — your organiser name, event and the consent wording (with retention filled in), a link to your privacy notice, an "under 16" option that asks for a parent or guardian, and an equally prominent "No thanks, I'll use the standard entrance".
  2. Camera — a live view with a face guide (front camera), or "Upload a photo instead".
  3. Check — "Happy with this photo?", retake or send. Unusable photos (no face, two faces, too small) are explained and can be retaken — up to 5 attempts per token.
  4. Done — "You're all set", plus when their face data will be deleted.

No website changes needed: send a guest a link instead. In Dashboard → event → Ticket page widget → Guest link, enter the ticket number, pick how long it's valid and copy the link. From your server, pass validForHours (up to 336, never past the event's end) and send the returned url:

curl -X POST https://api-eu.faceping.ai/v1/events/$EVENT_ID/enrolment-tokens \
  -H "X-Api-Key: $FACEPING_API_KEY" -H "Content-Type: application/json" \
  -d '{ "ticketId": "ACME-000123", "validForHours": 168 }'

Links work once and only for that ticket — send each one only to its ticket holder.

Your website's security policy#

If your site sends a Content-Security-Policy header, allow the widget:

script-src https://faceping.ai;
frame-src  https://faceping.ai;

The iframe asks for the camera (allow="camera"); nothing else on your page gets access to it.