Skip to main content
Version: Latest (4.0.5)

ID validator Modes Configuration

Verification Modes

A mode is the primary security profile of an ID validation.
It decides which process steps run, how deep document and biometric checks go, how many retries a user gets, and whether a successful result may be stored for reuse.

A configuration (ID validation Setting) binds a mode to theme, consent, prevalidation, and document data matching — then your backend creates cases against that setting.

Start here

Pick a mode cluster by business goal → pick a mode by risk/assurance → fine-tune optional steps in the configuration.


Mode vs. configuration​

LayerWhat it controlsWho chooses it
Mode clusterBusiness purpose (identity, age, onboarding)Product / compliance
ModeRequired steps, biometric depth, retries, reuse rulesAdmin UI dropdown ID validation Mode
ConfigurationTheme, consent, optional prevalidation & data matchingAdmin UI ID validation Settings
Modes are not free-form

You do not freely toggle every step on/off for every mode.
Modes enforce a security envelope. Optional features (prevalidation, document data matching, consent capture) are configured on top — where the mode allows them.


Mode clusters​

Cluster · Identity

Ident

Verify who someone is — from a simple document check to full eIDAS-grade verification with QES.

Cluster · Age

Age Verification

Confirm age thresholds (e.g. 16+, 18+, 21+) with the right friction for retail, gaming, or regulated goods.

Cluster · Onboarding

Onboarding

Combine identity checks with business context (employee ID, contract reference) for HR, fintech, and marketplaces.


Choose a mode​

Quick decision guide​

If you need…PreferWhy
Document authenticity only, no faceIdentCard / AgeCheckCardLowest friction
Identity + face + liveness (non-regulated KYC)IdentLight / IdentPhotoStrong fraud resistance without eIDAS constraints
eIDAS / high assurance / QESIdentEidasStrictest checks; result not reusable
Fast age gateAgeCheckCard or AgeCheckLightAge outcome without full KYC overhead
Strict age-controlled accessAgeCheckEssentialDocument + face + stronger checks
Digital onboarding with contextOnboardingLight / OnboardingEssentialIdentity + prevalidation-friendly flows

Process steps at a glance​

SymbolMeaning
✔ RequiredAlways executed for this mode
⭐ RecommendedStrongly advised; enable in configuration when available
◯ OptionalCustomer can enable/disable in the configuration (where supported)
❌ Not includedNot available for this mode

Mode matrix​

ClusterModePrevalidationDocument scanData matchingFace scanLivenessFace matchQESTypical use
IdentIdentCard◯✔⭐❌❌❌❌Simple document KYC
IdentIdentPhoto◯✔◯✔—*✔❌Doc + still photo match
IdentIdentLight◯✔◯✔✔✔❌Advanced non-regulated KYC
IdentIdentEidas⭐✔⭐✔✔✔✔Finance, insurance, QES
AgeAgeCheckCard◯✔⭐❌❌❌❌Low-friction age check
AgeAgeCheckLight◯✔◯✔✔✔❌Entertainment / gaming
AgeAgeCheckEssential◯✔⭐✔✔✔❌Tobacco, strict age gates
OnboardingOnboardingLight◯✔◯✔✔✔❌Fintech, marketplaces
OnboardingOnboardingEssential⭐✔⭐✔✔✔❌HR, banking onboarding

* IdentPhoto focuses on document + portrait comparison; use IdentLight when full liveness is required.

QES

Qualified Electronic Signature (QES) is available only in IdentEidas.


Document requirements​

Supported document categories include national identity cards, passports, residence permits, and (where enabled for the tenant) driver licenses. Coverage is country- and template-specific — not every national format is available in every mode.

Machine Readable Zone (MRZ)​

Most identity cards, passports, and residence permits expose an ICAO MRZ. Driver licenses in the seeded templates typically do not. During document scan the ID validator can:

  • read and parse the MRZ
  • validate MRZ checksums (MRZ_CHECKSUM)
  • cross-check MRZ data against other extracted document fields (MRZ_MATCH)

Whether those checks must succeed depends on the mode’s processing settings (mandatory flag):

ModeMRZ_CHECKSUM / MRZ_MATCH
AgeCheckEssential, OnboardingEssentialMandatory — the document template must expose MRZ fields; a missing/unreadable MRZ fails the scan
IdentCard, IdentLight, IdentPhoto, AgeCheckCard, AgeCheckLight, OnboardingLightConditional — checks run only when the chosen document template contains the required MRZ fields; templates without MRZ (e.g. many driver licenses) can still complete
How “conditional” works

If a security check is not marked mandatory, it is performed only when the document configuration includes the required text fields (for MRZ: typically mrz, plus match fields such as name, DOB, expiry, document number).

Practical implication

For AgeCheckEssential and OnboardingEssential, plan on users presenting an MRZ-capable document with a clear, complete zone. For other modes, MRZ quality still matters whenever the template has an MRZ — cropped or blurred captures fail those checks even when they are not globally mandatory.

Mode-specific document notes​

Document typeTypical modesNotes
ID card / passport / residence permitIdent*, Age*, Onboarding*Primary path; almost all seeded I/P/R templates include MRZ
Driver licenseNon-eIDAS Ident / Age / Onboarding profiles where enabledSeeded driver templates generally lack MRZ — fine for modes with conditional MRZ; unsuitable for AgeCheckEssential / OnboardingEssential
Documents without MRZModes with conditional MRZ onlyAvoid Essential age/onboarding modes unless you restrict to MRZ-capable document types

For the exact country/template list on your tenant, contact cidaas sales / support — the public docs do not list every integrated card template.


Mode catalog​

Ident​

IdentCard​

Basic ID document validation without face matching.

Best for: loyalty programs, low-trust KYC, document authenticity only.

Doc scanNo faceRetries: 3Result reusable

IdentPhoto​

Document scan plus comparison against a captured photo / portrait.

Best for: confirming the person matches the document without a full eIDAS flow.

Doc + face matchRetries: 3Result reusable

IdentLight​

Lightweight identity verification with face capture, liveness, and face matching.

Best for: advanced KYC outside regulated eIDAS scenarios.

Doc + liveness + matchRetries: 2Result reusable

IdentEidas​

Full eIDAS-aligned verification including the strongest biometric and document checks, with QES support.

Best for: finance, insurance, telecom, and other high-assurance use cases.

Prevalidation recommendedQESRetries: 1Result not reusable
eIDAS & result storage

For IdentEidas, verified identity results must not be stored for reuse. Each regulated verification must be performed anew.

Age Verification​

AgeCheckCard​

Age check from document analysis only — no face capture.

Best for: retail, delivery, low-friction age gates.

Doc onlyRetries: 3Result reusable

AgeCheckLight​

Document plus light face / liveness check for quicker age verification.

Best for: entertainment, gambling, e-commerce.

Doc + faceRetries: 3Result reusable

AgeCheckEssential​

Robust age verification with document security checks and full face analysis.

Best for: tobacco and other strictly age-controlled services.

Stronger checksRetries: 2Result reusable

Onboarding​

OnboardingLight​

Streamlined onboarding with document and face verification.

Best for: fintech and marketplace signup where conversion matters.

Prevalidation optionalRetries: 3Result reusable

OnboardingEssential​

Enhanced onboarding with stronger document + face verification and recommended prevalidation / data matching.

Best for: HR onboarding, banking, verified communities.

Prevalidation recommendedRetries: 2Result reusable

Optional configuration layers​

These are set in the Admin UI for each configuration — they do not replace the mode.

OptionWhat it doesEspecially useful for
ConsentCollect processing consent in-flow, or require it via API when disabledAll modes
PrevalidationAsk / verify business-context fields before the scan (contract ID, employee number, …)IdentEidas, OnboardingEssential
Document data matchingCompare API-supplied reference data with OCR/MRZ fields extracted from the document — see how it worksIdentEidas, onboarding, high-assurance Ident
ThemeBranding of the ID validator WebAppAll modes
Age verification tip

Document data matching is often less relevant for age gates when users register with pseudonyms. Prefer authenticity + (optional) face checks instead.

→ Step-by-step Admin UI: Creating a configuration
→ API payload fields: Integration Guide


Next steps​

  1. Select the mode that matches your risk and regulation profile.
  2. Create an ID validator configuration with that mode.
  3. Wire webhooks and start cases via the Integration Guide.