Blink KYC · New from Blink Pay

Know your customer, in seconds.

Blink KYC is drop-in identity verification: your backend mints a session, our SDK captures the document and the face, and you read back one clear verdict — VERIFIED, REJECTED or REVIEW. Arabic-first, replay-resistant, and deployable inside Sudan.

Document · Passport
Fields extracted · Arabic OCR
Liveness passed · Face matched
VERIFIED
Why Blink KYC

Built for how identity actually works here.

Four properties the rest of the product hangs off.

Arabic first

OCR reads Arabic and English documents natively — built for Sudanese passports, national IDs and driving licences, not adapted to them.

One clear verdict

VERIFIED, REJECTED or REVIEW, with a neutral reason. No scores to misread, no thresholds to leak.

Replay-resistant

Every capture step is gated by a single-use nonce, and the client secret never touches the device.

Deploys your way

Managed cloud or on-premise inside Sudan — identity data can stay in the country.

What it does

From camera to verdict.

The SDK owns the capture; the engine owns the decision. You own the customer.

Read the document, not just photograph it.

The SDK guides the customer to a clean capture, then the engine extracts the fields — names, numbers, dates — ready for your workflow.

  • Passports, national ID cards and driving licences
  • Arabic and English OCR, built for Sudanese documents
  • Quality checks reject blur and glare before submission
  • Extracted fields returned to your system, not just an image

Confirm a real person is really there.

Active liveness challenges the customer with randomised actions, then the face is matched against the document photo. Photos of photos and replays are turned away.

  • Active liveness with randomised challenges
  • Face matched against the document photo
  • A single-use challenge nonce for every step
  • Active and passive liveness, tuned per client

A black box that answers plainly.

Integrators get a verdict and a neutral reason — never thresholds or engine detail that could teach fraudsters. Borderline cases park for your staff, with the evidence and a full audit trail.

  • The authoritative verdict is fetched by your backend, never trusted from the device
  • REVIEW cases queue in a back-office console for your team
  • Matching policy set per client: park for sign-off, or proceed
  • Every decision recorded for audit
Security architecture

Designed so the weak link isn't ours.

The trust boundary is explicit: credentials stay on your server, the device holds a short-lived token, and the verdict you act on is fetched server-to-server.

The secret stays server-side

Sessions are minted server-to-server; the device only ever holds a short-lived, opaque token.

Nothing to replay

Each capture step redeems a single-use nonce — a captured request cannot be submitted twice.

Hashed, revocable credentials

Client secrets are stored bcrypt-hashed and session handles only as digests. Revocation is instant.

Isolation in the database

Tenant separation is enforced by PostgreSQL row-level security — the application cannot bypass controls it is subject to.

Deployment

Run it where your regulator is comfortable.

Same engine, two homes — our managed cloud, or servers inside Sudan.

Managed cloud

Integrate against kyc-api.blink-pay.net and be capturing documents the same week. We run it, meter it and keep it patched.

  • Sandbox clients with deterministic outcomes
  • Metered usage, quotas and reporting per client

On-premise, in-country

The same engine, deployed on infrastructure inside Sudan — for banks whose regulator wants identity data to stay home.

  • In-country data residency
  • Encrypted document store on your hardware
First in the product line

Update-KYC: re-verify existing customers at scale.

The first product built on the engine. Banks refresh the files of customers they already have: a bilingual customer portal, a case state-machine with staff sign-off, matching against the core-banking record, and sync back when the case closes.

Questions

Asked often, answered plainly.

Which documents can it read?

Passports, Sudanese national ID cards and driving licences, with OCR that reads Arabic and English natively. Quality checks reject blurred or glared captures before they are submitted.

How long does integration take?

A sandbox integration is typically a day's work: mint a session, drop the SDK into your app, read the verdict. Going live is credential issuance plus registering your web origins.

Where does the data live?

Your choice: our managed cloud, or an on-premise deployment inside Sudan. Documents are encrypted at rest, and devices only ever see the verdict — never the underlying data.

How is it priced?

Usage is metered per verification, with quotas and reporting per client. Commercial terms depend on volume and deployment — talk to us for a quote.

Can our own staff review borderline cases?

Yes. Cases that come back REVIEW park in a back-office console for your team, with the evidence and a full audit trail. Your policy decides what parks and what proceeds.

See onboarding at Blink speed.

A live demo on your use case, or sandbox credentials to start building today.

Book a demo