Skip to main content
Everything about a workspace is on its page under Workspaces in the console. What a workspace is, and why you need a test and a live one, is on Concepts.

Create a workspace

Create Workspace asks:
  • What should this workspace check?
    • Identity (KYC): the person scans their ID and takes a selfie. API: flow_type: kyc.
    • Age verification → ID document (Highest assurance): the same capture as Identity, plus your minimum age, from 16 to 25. API: flow_type: age, age_mode: document_verification.
    • Age verification → Facial age estimation (Fast & easy): a selfie, 18+ only. When the selfie can’t confirm 18+, the person adds an ID in the same session; nobody is declined on the selfie alone. API: flow_type: age, age_mode: estimation.
  • Mode: Live (the default) or Test. A test workspace runs the real widget, but nothing is analysed or billed and you choose each outcome yourself. The mode cannot be changed later.
  • A name your team recognises.
Identity versus age verification is fixed once the workspace exists. An age workspace can later switch between its two methods and change its minimum age. On the workspace’s page these appear as Verification, Method and Minimum age. Administrators and developers can create and change workspaces; support specialists can see them.

Settings

The page also shows ready-to-paste integration code for the Browser SDK, in a modal or a new tab, with the workspace’s public key filled in. A workspace can be suspended: its API answers 403 WORKSPACE_SUSPENDED and its open links stop working, until you reactivate it.

Keys

Store secret keys in environment variables or a secrets manager, never in source control or client-side code. How they are used is on API authentication.

Rotate a secret key without downtime

1

Create a new key

Add a secret key on the workspace’s page. The old one keeps working.
2

Deploy it

Sign API requests with the new key. In your webhook handler, accept a signature made with either key for now.
3

Make it active

Set the new key as active. From now on webhooks are signed with it.
4

Delete the old key

Once nothing uses it, delete it: requests signed with it are refused from then on. Remove it from your webhook handler too.
If you reach five keys, delete an unused one before creating another. The active key cannot be deleted; make another one active first.