WKYC Identity Verification Addon
Use WKYC to send clients through hosted identity checks, return signed provider verdicts into WISECP document-verification records, and enforce those results with the existing field and filter system without storing identity images locally.
Reaching the Screen
Go to Tools → Add-ons → WKYC: {admin}/tools/addons/WKYC
This module is included with the Business Plan at no additional cost. On other WISECP license plans you can add it to your existing license.
The page remains visible for configuration review while the add-on is disabled. Creating sessions, processing callbacks and exposing the external-verification field require the module to be enabled and the license to be active.
What the Add-on Does
| Area | Administrator capability | Client/compliance result |
|---|---|---|
| Providers | Configure and test Didit, ComplyCube, Veriff, Persona, Stripe Identity, Sumsub, Shufti, Onfido or iDenfy credentials independently. The list is ordered by state and each row states its status in one sentence. | Only enabled providers with every required credential can be assigned to a verification field. |
| Hosted verification | Create an External Verification document field with a provider and verification level/options. | The client continues on the provider-hosted identity flow; WISECP does not collect the document image for that field. |
| Policy enforcement | Attach the field to document-verification filters that select which clients must verify. | Core verification status and filters consume the provider verdict like other document records. |
| Session operations | Monitor statistics/recent sessions, refresh pending results and delete locally or request provider purge. | Attempts, pending sessions and final decisions remain traceable to client, field, filter and provider. |
Provider and credential functions
Every provider card declares its own required keys, secrets, template/workflow identifiers and optional environment switches. The card supplies provider-console guidance, a connection test and readiness status. A provider is selectable only when it is both enabled and fully configured. Secret fields retain stored values when left blank; typed values can be tested before saving. A single default provider is used by fields that do not pin another ready provider.
Verification and policy functions
WKYC adds the External Verification type to document-verification fields. Instead of a file input, eligible clients get an action that creates or resumes a hosted session. A still-open session is reused so leaving and returning does not consume another attempt. Webhook decisions are written to the field record; pending sessions can also be refreshed from the provider. The standard verification filter then controls which client population must complete that field, and an attempt ceiling protects provider credit from endless retries.
Session and evidence functions
The administration page shows verification totals and a searchable recent-session table with client, field, provider, session reference, status and time. Expired stale sessions are reconciled when the page loads. Deleting removes the local session/evidence history; the optional purge also asks the provider associated with that session to erase its copy when supported. The read-only webhook URL is the callback target to register in provider consoles that require one.
Before You Configure It
- Enable WKYC and confirm its license, then select a provider that supports your countries, document types, verification level and retention requirements.
- Create the provider account/application, credentials and billing arrangement. Prepare any provider template/workflow and webhook signing secret required by its card.
- Confirm the public WISECP API callback is reachable by the provider and that your privacy notice, lawful basis, retention and support process cover hosted identity checks.
- Decide which client group needs verification and prepare a test client whose profile name and documents represent the intended flow.
Provider and Verification Controls
Installation and Operation
Select and prepare a provider
- Compare the supported providers against required countries, documents, liveness/identity policy, data location, retention, pricing and expected volume.
- Create the provider-side application/template/workflow and credentials shown by its WKYC card.
- Restrict credentials to the intended environment and record who owns credit monitoring, key rotation and incident revocation.
Connect, test and register callbacks
- Open the provider card, enter every required non-secret/secret value, enable it and run Test Connection before saving.
- Where the card requires callbacks, copy the read-only Webhook Address into the provider console, select the listed decision events and store the provider-generated signing secret in the matching field.
- Save settings, then pick a ready default provider in the Verification Behaviour section and save again. The first usable provider becomes available in External Verification fields.
Build the field and filter flow
- Create a document-verification field with External Verification type; choose Default or a specific ready provider and set its verification level/options.
- Create or edit a document-verification filter, attach that field and narrow the audience to the exact clients who must pass KYC.
- Review the client verification tab with a matching test client. The field should show the hosted action instead of a local file upload.
Verify the complete client session
- Start the test verification, leave once and return to confirm the open session resumes instead of creating a chargeable duplicate.
- Complete the provider flow and verify the webhook or refresh changes the WISECP document record to the expected status.
- Test a rejected/requires-input result and the attempt ceiling, then confirm the filter allows or blocks the client exactly as intended.
Monitor sessions and provider health
- Read the total and the Approved, Declined, In Progress and No verdict split in the Verifications section. Then search by client, provider or session and investigate long-pending records.
- Compare provider-side status with the WISECP record when callbacks fail, then fix callback reachability/signature configuration before retrying.
- Track attempt volume and provider credits so filter mistakes or repeated client failures do not create uncontrolled cost.
Delete or purge a session
- Locate the exact session and confirm its client, field, provider, status and retention obligation.
- Choose local deletion only, or provider purge when the external copy must also be removed and the provider supports it.
- Confirm the irreversible action. The local history disappears and provider purge is requested using that session’s own provider.
Maintain credentials and policy
- Rotate provider credentials and webhook secrets, test before saving, and confirm existing fields still resolve to a ready provider.
- Review filters, profile-name quality, attempt counts, provider pricing and retention policy on a fixed schedule.
- Repeat an end-to-end session after provider template/event changes; disable a provider before its credentials or compliance basis becomes invalid.
Things to Watch
Local deletion removes WISECP session history; provider purge can permanently remove the external record too. Confirm retention obligations first.
Old, abbreviated, transliterated or differently ordered profile names may not match a valid document. Enable it only when profile data is dependable.
The add-on reuses an open session and enforces an attempt ceiling, but each new provider check may consume credit. Keep filter scope narrow.
Privileges
Tools Add-ons (TOOLS_ADDONS) is required for providers and sessions. Creating fields/filters and reviewing records also requires the corresponding client document-verification privileges.
Related Screens
Merci pour votre retour !
Notre équipe d'assistance est disponible 24h/24 pour tout ce que vous ne trouvez pas ci-dessus.