Verification Modes
A mode is the primary security profile of an ID validation.
It decides which process steps run, how deep document and biometric checks go, how many retries a user gets, and whether a successful result may be stored for reuse.
A configuration (ID validation Setting) binds a mode to theme, consent, prevalidation, and document data matching — then your backend creates cases against that setting.
Pick a mode cluster by business goal → pick a mode by risk/assurance → fine-tune optional steps in the configuration.
Mode vs. configuration
| Layer | What it controls | Who chooses it |
|---|---|---|
| Mode cluster | Business purpose (identity, age, onboarding) | Product / compliance |
| Mode | Required steps, biometric depth, retries, reuse rules | Admin UI dropdown ID validation Mode |
| Configuration | Theme, consent, optional prevalidation & data matching | Admin UI ID validation Settings |
You do not freely toggle every step on/off for every mode.
Modes enforce a security envelope. Optional features (prevalidation, document data matching, consent capture) are configured on top — where the mode allows them.
Mode clusters
Ident
Verify who someone is — from a simple document check to full eIDAS-grade verification with QES.
Age Verification
Confirm age thresholds (e.g. 16+, 18+, 21+) with the right friction for retail, gaming, or regulated goods.
Onboarding
Combine identity checks with business context (employee ID, contract reference) for HR, fintech, and marketplaces.
Choose a mode
Quick decision guide
| If you need… | Prefer | Why |
|---|---|---|
| Document authenticity only, no face | IdentCard / AgeCheckCard | Lowest friction |
| Identity + face + liveness (non-regulated KYC) | IdentLight / IdentPhoto | Strong fraud resistance without eIDAS constraints |
| eIDAS / high assurance / QES | IdentEidas | Strictest checks; result not reusable |
| Fast age gate | AgeCheckCard or AgeCheckLight | Age outcome without full KYC overhead |
| Strict age-controlled access | AgeCheckEssential | Document + face + stronger checks |
| Digital onboarding with context | OnboardingLight / OnboardingEssential | Identity + prevalidation-friendly flows |
Process steps at a glance
| Symbol | Meaning |
|---|---|
| ✔ Required | Always executed for this mode |
| ⭐ Recommended | Strongly advised; enable in configuration when available |
| ◯ Optional | Customer can enable/disable in the configuration (where supported) |
| ❌ Not included | Not available for this mode |
Mode matrix
| Cluster | Mode | Prevalidation | Document scan | Data matching | Face scan | Liveness | Face match | QES | Typical use |
|---|---|---|---|---|---|---|---|---|---|
| Ident | IdentCard | ◯ | ✔ | ⭐ | ❌ | ❌ | ❌ | ❌ | Simple document KYC |
| Ident | IdentPhoto | ◯ | ✔ | ◯ | ✔ | —* | ✔ | ❌ | Doc + still photo match |
| Ident | IdentLight | ◯ | ✔ | ◯ | ✔ | ✔ | ✔ | ❌ | Advanced non-regulated KYC |
| Ident | IdentEidas | ⭐ | ✔ | ⭐ | ✔ | ✔ | ✔ | ✔ | Finance, insurance, QES |
| Age | AgeCheckCard | ◯ | ✔ | ⭐ | ❌ | ❌ | ❌ | ❌ | Low-friction age check |
| Age | AgeCheckLight | ◯ | ✔ | ◯ | ✔ | ✔ | ✔ | ❌ | Entertainment / gaming |
| Age | AgeCheckEssential | ◯ | ✔ | ⭐ | ✔ | ✔ | ✔ | ❌ | Tobacco, strict age gates |
| Onboarding | OnboardingLight | ◯ | ✔ | ◯ | ✔ | ✔ | ✔ | ❌ | Fintech, marketplaces |
| Onboarding | OnboardingEssential | ⭐ | ✔ | ⭐ | ✔ | ✔ | ✔ | ❌ | HR, banking onboarding |
* IdentPhoto focuses on document + portrait comparison; use IdentLight when full liveness is required.
Qualified Electronic Signature (QES) is available only in IdentEidas.
Document requirements
Supported document categories include national identity cards, passports, residence permits, and (where enabled for the tenant) driver licenses. Coverage is country- and template-specific — not every national format is available in every mode.
Machine Readable Zone (MRZ)
Most identity cards, passports, and residence permits expose an ICAO MRZ. Driver licenses in the seeded templates typically do not. During document scan the ID validator can:
- read and parse the MRZ
- validate MRZ checksums (
MRZ_CHECKSUM) - cross-check MRZ data against other extracted document fields (
MRZ_MATCH)
Whether those checks must succeed depends on the mode’s processing settings (mandatory flag):
| Mode | MRZ_CHECKSUM / MRZ_MATCH |
|---|---|
| AgeCheckEssential, OnboardingEssential | Mandatory — the document template must expose MRZ fields; a missing/unreadable MRZ fails the scan |
| IdentCard, IdentLight, IdentPhoto, AgeCheckCard, AgeCheckLight, OnboardingLight | Conditional — checks run only when the chosen document template contains the required MRZ fields; templates without MRZ (e.g. many driver licenses) can still complete |
If a security check is not marked mandatory, it is performed only when the document configuration includes the required text fields (for MRZ: typically mrz, plus match fields such as name, DOB, expiry, document number).
For AgeCheckEssential and OnboardingEssential, plan on users presenting an MRZ-capable document with a clear, complete zone. For other modes, MRZ quality still matters whenever the template has an MRZ — cropped or blurred captures fail those checks even when they are not globally mandatory.
Mode-specific document notes
| Document type | Typical modes | Notes |
|---|---|---|
| ID card / passport / residence permit | Ident*, Age*, Onboarding* | Primary path; almost all seeded I/P/R templates include MRZ |
| Driver license | Non-eIDAS Ident / Age / Onboarding profiles where enabled | Seeded driver templates generally lack MRZ — fine for modes with conditional MRZ; unsuitable for AgeCheckEssential / OnboardingEssential |
| Documents without MRZ | Modes with conditional MRZ only | Avoid Essential age/onboarding modes unless you restrict to MRZ-capable document types |
For the exact country/template list on your tenant, contact cidaas sales / support — the public docs do not list every integrated card template.
Mode catalog
Ident
IdentCard
Basic ID document validation without face matching.
Best for: loyalty programs, low-trust KYC, document authenticity only.
IdentPhoto
Document scan plus comparison against a captured photo / portrait.
Best for: confirming the person matches the document without a full eIDAS flow.
IdentLight
Lightweight identity verification with face capture, liveness, and face matching.
Best for: advanced KYC outside regulated eIDAS scenarios.
IdentEidas
Full eIDAS-aligned verification including the strongest biometric and document checks, with QES support.
Best for: finance, insurance, telecom, and other high-assurance use cases.
For IdentEidas, verified identity results must not be stored for reuse. Each regulated verification must be performed anew.
Age Verification
AgeCheckCard
Age check from document analysis only — no face capture.
Best for: retail, delivery, low-friction age gates.
AgeCheckLight
Document plus light face / liveness check for quicker age verification.
Best for: entertainment, gambling, e-commerce.
AgeCheckEssential
Robust age verification with document security checks and full face analysis.
Best for: tobacco and other strictly age-controlled services.
Onboarding
OnboardingLight
Streamlined onboarding with document and face verification.
Best for: fintech and marketplace signup where conversion matters.
OnboardingEssential
Enhanced onboarding with stronger document + face verification and recommended prevalidation / data matching.
Best for: HR onboarding, banking, verified communities.
Optional configuration layers
These are set in the Admin UI for each configuration — they do not replace the mode.
| Option | What it does | Especially useful for |
|---|---|---|
| Consent | Collect processing consent in-flow, or require it via API when disabled | All modes |
| Prevalidation | Ask / verify business-context fields before the scan (contract ID, employee number, …) | IdentEidas, OnboardingEssential |
| Document data matching | Compare API-supplied reference data with OCR/MRZ fields extracted from the document — see how it works | IdentEidas, onboarding, high-assurance Ident |
| Theme | Branding of the ID validator WebApp | All modes |
Document data matching is often less relevant for age gates when users register with pseudonyms. Prefer authenticity + (optional) face checks instead.
→ Step-by-step Admin UI: Creating a configuration
→ API payload fields: Integration Guide
Next steps
- Select the mode that matches your risk and regulation profile.
- Create an ID validator configuration with that mode.
- Wire webhooks and start cases via the Integration Guide.