WKYC Identity Verification Addon

106 vues Markdown

Use WKYC to send clients through hosted identity checks, return signed provider verdicts into WISECP document-verification records, and enforce those results with the existing field and filter system without storing identity images locally.

Reaching the Screen

Go to Tools → Add-ons → WKYC: {admin}/tools/addons/WKYC

Premium Feature

This module is included with the Business Plan at no additional cost. On other WISECP license plans you can add it to your existing license.

The page remains visible for configuration review while the add-on is disabled. Creating sessions, processing callbacks and exposing the external-verification field require the module to be enabled and the license to be active.

What the Add-on Does

AreaAdministrator capabilityClient/compliance result
ProvidersConfigure and test Didit, ComplyCube, Veriff, Persona, Stripe Identity, Sumsub, Shufti, Onfido or iDenfy credentials independently. The list is ordered by state and each row states its status in one sentence.Only enabled providers with every required credential can be assigned to a verification field.
Hosted verificationCreate an External Verification document field with a provider and verification level/options.The client continues on the provider-hosted identity flow; WISECP does not collect the document image for that field.
Policy enforcementAttach the field to document-verification filters that select which clients must verify.Core verification status and filters consume the provider verdict like other document records.
Session operationsMonitor statistics/recent sessions, refresh pending results and delete locally or request provider purge.Attempts, pending sessions and final decisions remain traceable to client, field, filter and provider.

Provider and credential functions

Every provider card declares its own required keys, secrets, template/workflow identifiers and optional environment switches. The card supplies provider-console guidance, a connection test and readiness status. A provider is selectable only when it is both enabled and fully configured. Secret fields retain stored values when left blank; typed values can be tested before saving. A single default provider is used by fields that do not pin another ready provider.

Verification and policy functions

WKYC adds the External Verification type to document-verification fields. Instead of a file input, eligible clients get an action that creates or resumes a hosted session. A still-open session is reused so leaving and returning does not consume another attempt. Webhook decisions are written to the field record; pending sessions can also be refreshed from the provider. The standard verification filter then controls which client population must complete that field, and an attempt ceiling protects provider credit from endless retries.

Session and evidence functions

The administration page shows verification totals and a searchable recent-session table with client, field, provider, session reference, status and time. Expired stale sessions are reconciled when the page loads. Deleting removes the local session/evidence history; the optional purge also asks the provider associated with that session to erase its copy when supported. The read-only webhook URL is the callback target to register in provider consoles that require one.

Before You Configure It

  1. Enable WKYC and confirm its license, then select a provider that supports your countries, document types, verification level and retention requirements.
  2. Create the provider account/application, credentials and billing arrangement. Prepare any provider template/workflow and webhook signing secret required by its card.
  3. Confirm the public WISECP API callback is reachable by the provider and that your privacy notice, lawful basis, retention and support process cover hosted identity checks.
  4. Decide which client group needs verification and prepare a test client whose profile name and documents represent the intended flow.

Provider and Verification Controls

Provider EnabledA provider becomes usable only when enabled and all of its required credential fields are complete.
Provider CredentialsRequirements vary by provider and may include API keys, secrets, account/project, template or workflow identifiers and environment selection.
Default ProviderSits in the Verification Behaviour section. Used by new or existing external fields that keep their provider selection on Default.
Match Profile NameSits in the Verification Behaviour section. When enabled, sends the account name for comparison with the verified document; reliable profile naming is required.
Webhook AddressSits in the Verification Behaviour section. Read-only public callback registered in providers that use webhooks; provider-specific events and signing secrets still follow the card instructions.
Field ProviderAn External Verification field can pin a ready provider or follow the module default.
Verification Level / OptionsSaved on the external field and determines the provider flow requested for clients.

Installation and Operation

Select and prepare a provider

  1. Compare the supported providers against required countries, documents, liveness/identity policy, data location, retention, pricing and expected volume.
  2. Create the provider-side application/template/workflow and credentials shown by its WKYC card.
  3. Restrict credentials to the intended environment and record who owns credit monitoring, key rotation and incident revocation.

Connect, test and register callbacks

  1. Open the provider card, enter every required non-secret/secret value, enable it and run Test Connection before saving.
  2. Where the card requires callbacks, copy the read-only Webhook Address into the provider console, select the listed decision events and store the provider-generated signing secret in the matching field.
  3. Save settings, then pick a ready default provider in the Verification Behaviour section and save again. The first usable provider becomes available in External Verification fields.

Build the field and filter flow

  1. Create a document-verification field with External Verification type; choose Default or a specific ready provider and set its verification level/options.
  2. Create or edit a document-verification filter, attach that field and narrow the audience to the exact clients who must pass KYC.
  3. Review the client verification tab with a matching test client. The field should show the hosted action instead of a local file upload.

Verify the complete client session

  1. Start the test verification, leave once and return to confirm the open session resumes instead of creating a chargeable duplicate.
  2. Complete the provider flow and verify the webhook or refresh changes the WISECP document record to the expected status.
  3. Test a rejected/requires-input result and the attempt ceiling, then confirm the filter allows or blocks the client exactly as intended.

Monitor sessions and provider health

  1. Read the total and the Approved, Declined, In Progress and No verdict split in the Verifications section. Then search by client, provider or session and investigate long-pending records.
  2. Compare provider-side status with the WISECP record when callbacks fail, then fix callback reachability/signature configuration before retrying.
  3. Track attempt volume and provider credits so filter mistakes or repeated client failures do not create uncontrolled cost.

Delete or purge a session

  1. Locate the exact session and confirm its client, field, provider, status and retention obligation.
  2. Choose local deletion only, or provider purge when the external copy must also be removed and the provider supports it.
  3. Confirm the irreversible action. The local history disappears and provider purge is requested using that session’s own provider.

Maintain credentials and policy

  1. Rotate provider credentials and webhook secrets, test before saving, and confirm existing fields still resolve to a ready provider.
  2. Review filters, profile-name quality, attempt counts, provider pricing and retention policy on a fixed schedule.
  3. Repeat an end-to-end session after provider template/event changes; disable a provider before its credentials or compliance basis becomes invalid.

Things to Watch

Deleting identity evidence is irreversible

Local deletion removes WISECP session history; provider purge can permanently remove the external record too. Confirm retention obligations first.

Name matching can reject genuine clients

Old, abbreviated, transliterated or differently ordered profile names may not match a valid document. Enable it only when profile data is dependable.

Provider attempts are billed externally

The add-on reuses an open session and enforces an attempt ceiling, but each new provider check may consume credit. Keep filter scope narrow.

Privileges

Tools Add-ons (TOOLS_ADDONS) is required for providers and sessions. Creating fields/filters and reviewing records also requires the corresponding client document-verification privileges.

Cet article vous a-t-il été utile ?

Merci pour votre retour !

Besoin d'aide supplémentaire ?

Notre équipe d'assistance est disponible 24h/24 pour tout ce que vous ne trouvez pas ci-dessus.