Skip to main content
You sell alcohol, tobacco, vapes or other age-restricted goods, and the law requires checking the buyer’s age before the sale. This recipe verifies the buyer once, at checkout, and remembers the result on their account.
On WordPress with WooCommerce, the plugin does all of this without code. On Shopify, see the Shopify app; on PrestaShop, the module.

The workspace

  • Facial age estimation for the lightest check: a selfie, with a document only when the estimate cannot confirm the buyer is 18+.
  • Age verification by ID document when your rules require a document, or a minimum age other than 18 (16 to 25).

Steps

1

Check before payment

When a buyer reaches checkout with a restricted product, look up whether they are already verified on your side. If they are, continue.
2

Create a verification

On your backend, create a verification with the buyer’s ID and the page to return to:
Store verification.id with the buyer, and return verification.url to the page.
3

Open it

Open the url with the Browser SDK. Keep the payment button disabled.
4

Record the outcome

In your webhook handler:
5

Let the order through

When the buyer is back on the checkout page, read their state from your database. Enable payment only if they are verified; if the webhook has not arrived yet, show “checking” and poll your own backend for a few seconds.

What to store

  • On the user: that they are age-verified, when, and the verification_id.
  • On each restricted order: the verification_id that allowed it, as evidence for an audit.

Edge cases

  • The buyer closes the widget. Nothing changes; the next checkout attempt opens the same verification if it is still open, or you create a new one after it is abandoned or expired.
  • Resubmission requested. The widget asks the buyer to retake the image in the same verification; wait for the next webhook. See Handle a resubmission.
  • Declined as underage. verification.age_threshold.failed: refuse the order. Do not offer an immediate new verification.
  • Guest checkout. Use the order ID or the email as external_id, and verify per order instead of per account.