ByteVerify · Built on x402

Is the face on camera the face on the ID?

Verify that the person on the other end is live and holding their own government ID.* Under a minute, from your software or your AI agent, before you release funds, change payment details or hand over a credential.

Send this to your agent
Read https://api.verify.bytefederal.com/skill.md and run a live face-to-ID check.
See the handshake Prefer an API key? Talk to us.
  • $2.00 per check, no account needed
  • 3D liveness, tested against injection
  • Recognized government-ID formats
  • Deleted within 24 hours
A woman holds a phone up to scan her face with one hand and a plain sample ID card beside her face with the other.

Pay per check. No account needed.

Each check is $2.00, paid in USDC over x402, the open payment standard AI agents already speak. An agent can call it, pay for it and act on the result on its own.

Verify, then delete.

The face scan, the ID images and the biometric template are destroyed when the check settles, within 24 hours at the latest. Nothing sits in a database waiting to leak.

Proven on our own customers first.

This is the liveness and ID technology Byte Federal uses to onboard its own customers, run on servers we operate and tested by independent labs. A licensed U.S. money services business stands behind every check.

Why this exists

Every online scam has one thing in common.
Nobody ever saw the person.

Wire fraud. Fake sellers. Cloned voices. Bot accounts. Before you move money for someone you have only met through a screen, make them hold their own ID up to a live camera.

  • $2.00per check
  • 30 secondsfor the person
  • 0stored after 24 hours
Prefer to watch?

The six-minute version.

Why this exists, how the check works, and what it costs. Captions included.

How it works

Send a link. The person scans. You get the answer.

  1. 01

    Request a check

    One POST with who is asking and where to send the result. You get back a single-use link. With x402, the same request settles the $2.00.

  2. 02

    Send the link

    By text, email, chat or inside your app. It stays open for 60 minutes.

  3. 03

    They scan face and ID

    The person sees who asked, agrees, and scans their face and their government ID on any phone. About 30 seconds. Once they start they have 30 minutes.

  4. 04

    You get the result. We delete the rest.

    verified, failed or expired, by signed webhook or one GET. The scan, the images and the template are destroyed. The record that a check happened is all that remains.

Built for agents

An agent can run this on its own.

ByteVerify speaks x402, the open HTTP payment standard. The first request comes back as a 402 with the price. The agent signs a USDC authorization, retries, and the check is created. Payment and setup are the same step, which is what lets an autonomous workflow pause for a human check before an irreversible move.

  • USDC on Base. Settles in seconds.
  • Standard Webhooks signing, so any common library can verify the callback.
  • One payment, one check. Retries are safe.
  • Invited teams can use an API key on the same endpoint.
Machine-readable manifest at /.well-known/x402.json
agent → api.verify.bytefederal.com
$ curl -X POST https://api.verify.bytefederal.com/v1/verifications \
    -d '{"originator":{"name":"Acme Escrow","title":"Payout desk"}}'

HTTP/1.1 402 Payment Required
{ "price": "2.00", "asset": "USDC", "network": "base", "payTo": "0x…" }

# agent signs a USDC authorization and retries with X-PAYMENT

HTTP/1.1 201 Created
{
  "verification_id":  "bv_8f3a2c",
  "verification_url": "https://api.verify.bytefederal.com/s/8f3a2c…",
  "status":           "pending",
  "expires_at":       "2026-09-02T15:04:00Z"
}

# about a minute later, your webhook receives:
{
  "verification_id":  "bv_8f3a2c",
  "status":           "verified",
  "completed_at":     "2026-09-02T14:05:12Z"
}
The check

How do we verify?*

Three checks, live, in one scan. All three pass and the result is verified. Otherwise it is failed.

Two hands: one holds a phone showing a face-scan guide, the other holds a plain sample ID card.
  1. A live human is in front of the camera

    A 3D liveness check built from 100+ frames in a few seconds, lab-tested against printed photos, screen replays, 3D masks, virtual cameras and injected video.

    must pass passed
  2. The face matches the photo on the ID

    The live 3D face is compared with the portrait on the document.

    must pass passed
  3. The document is a physical card in a known government-ID format

    The card is matched against known government-ID formats. Its barcode and machine-readable zone are read and cross-checked with the printed text.

    must pass passed

Where it matters

Three moments where one check changes the outcome.

Each one is an irreversible step taken on the word of someone you have only met through a screen.

Finance · payment details change
Dana · Acme Supplies

“We switched banks last week. Please send this month's payment to the new account below.”

What is at stake

Real mailbox, taken over on Tuesday. The confirming phone call is a cloned voice.

With ByteVerify

Send Dana a link before the change goes in. A stolen inbox and a cloned voice cannot pass a live scan with a matching ID.

"status": "expired" link never opened. Payment details stay as they were.
Agents · paying a counterparty
seller_88 · chat

“Deal. Send the deposit tonight and it ships tomorrow.”

What is at stake

An hour of negotiation with an account. Was a person ever on the other side, or a script running against a thousand buyers?

With ByteVerify

The agent pays $2, sends the link and waits. Live face and matching ID: deposit released. Silence or a failed scan: money stays put.

"status": "verified" 0:41 from link to result. Deposit released.
Marketplaces · releasing escrow
Escrow desk · internal

“Buyer funds cleared. Release to the seller today?”

What is at stake

A copied listing, someone else's photos, a wallet the seller has never seen. Once released, it is gone.

With ByteVerify

A live scan before any release above your threshold. Less than the transaction fee, under a minute, nothing kept afterwards.

"status": "failed" face did not match the ID. Release held for review.
Choosing a vendor

Six questions to ask any verification vendor.

Ours are answered on every card.

01

Face and ID, or face alone?

A face alone says a person exists. It cannot say they hold a credential with their own face on it.

Both, in one scan. Both must pass.

02

Which lab, and what level?

"Certified" with no level attached usually means Level 1, the easier tier.

iBeta Level 1 and 2. BixeLab injection, 48 of 48 rejected.

03

What do they keep afterwards?

Stored videos, templates and face indexes are what leaks and what gets subpoenaed.

Destroyed within 24 hours. No face index. Published policy.

04

A score, or an answer?

A score makes you the one who set the bar. A reason code shows attackers which check to beat.

verified, failed or expired. We own the threshold.

05

Can software buy it alone?

An agent cannot fill in a signup form or sit through a sales call.

Pay per call over x402. No account.

06

Who signs the contract?

A vendor is the counterparty you rely on at the moment of loss.

A licensed U.S. money transmitter, on servers it operates.

Independent testing

Tested by accredited labs.

The liveness and matching technology inside ByteVerify has been tested by NIST/NVLAP-accredited labs under the ISO standards for presentation attack detection and biometric performance. Every figure here traces to a named lab and a named test.

Figures as published by the technology's vendor from its third-party lab testing. They describe the technology itself; the fine print says what that covers.

0%
successful spoofs across 5,000+ presentation attacks in ISO/IEC 30107-3 testing
iBeta 2018–19 · BixeLab 2023
100%
of 48 camera-injection attacks rejected, including emulators, virtual cameras and API tampering
BixeLab 2025
0.005%
false-match rate at the recommended threshold, over 1,005,007 comparisons
BixeLab · ISO/IEC 19795-2
$600K
standing spoof bounty on the technology, open since 2019, covering injection attacks
Vendor program
The price

A live face is half of it. The ID is the other half.*

Checks that stop at the face are cheap because the face is the cheap part. Reading the document, checking it is a physical card, and matching its portrait to a live 3D face is the work, and it is what makes the result something you can act on.

One price, one product, nothing to unlock.

$2.00
per check, all of it: liveness, ID, face match, signed webhook, deletion
< $30
what a domestic wire fee typically costs. The check that protects the wire costs less than the wire.
0
images, templates or videos kept after 24 hours

Verify and forget

What we keep.

The face and the document are processed on servers we run, in a session that ends. This is the whole timeline.

  1. Request

    Who is asking and your reference. Nothing about the person yet.

  2. During transient

    Face scan, ID images and biometric template, on servers we operate. The software's maker never receives them.

  3. Result

    verified, failed or expired, plus a timestamp.

  4. ≤ 24 hours

    The images and template are destroyed. What remains is the record that a check happened, its result and the time.

Nothing to breach. The data a vendor keeps is the data that leaks. A breach here would yield check IDs, timestamps and results, and nothing anyone could be identified by.

Binding statement: our Biometric Data Retention and Destruction Policy.

Byte Federal

The check we run on our own customers.

The same liveness and document technology Byte Federal uses to onboard its own ATM customers.

Licensed U.S. money transmitter

Regulated in the states it serves. Regulator contacts are public.

Nationwide Bitcoin ATM network

Machines that meet the scams on this page every day.

Run on servers we operate

The liveness software runs on our own servers. Its maker never receives a face.

Published retention policy

What we keep and how it is destroyed, in writing.

Pricing

$ 2 .00

per check

That is the whole price list.

  • One price for every check. No account, no contract, no monthly minimum.
  • Pay per call in USDC via x402, or with an API key if you are an invited team.
  • Every check is billed when it is created, including ones that expire unopened. The 60-minute window is yours to manage.
  • Liveness, the government-ID check, a signed webhook and deletion are included every time.
  • Teams get an API key and volume pricing: the per-check price steps down with monthly volume, and committed volume earns a rebate.
Send this to your agent
Read https://api.verify.bytefederal.com/skill.md and run a live face-to-ID check.

Running more than a thousand checks a month, or want an API key for your team? Talk to us about volume pricing.

Questions

Three things: a live human was in front of the camera, the face matched the portrait on the document they held up, and that document was a physical card in a recognized government-ID format. It is a strong signal that the person holding the ID is the person on it. The fine print says exactly where it stops.
It is one part of one. A full identity check validates the document with the issuer, checks the person's details against records and ties the result to an account. ByteVerify does the part that is hardest to fake and easiest to delete, a live face against a physical ID, and stops there. Use it as a checkpoint inside your own process.
They are processed on infrastructure Byte Federal operates and destroyed as soon as the check settles, within 24 hours at the latest, whether it succeeded, failed or expired. The verification software runs on our own servers, so its maker never receives them. What remains is that a check happened, when, who asked and the result. Our published Biometric Data Retention and Destruction Policy is the binding statement.
Yes. ByteVerify speaks x402, the open HTTP payment standard. An unpaid request gets a 402 with the price. The agent signs a USDC authorization on Base, retries, and the check is created. The payment is the setup. One payment maps to exactly one check, so a retried request is safe.
The link expires after 60 minutes and the check settles as expired. You are told by webhook or on the next GET. Once a person starts, they have 30 minutes to finish, including retries. Every check is billed when it is created, expired ones included.
Because the face is the cheap part. A single frame through a liveness model tells you a person is present, and that is worth about what it costs. Every scenario on this page needs the next step: that the person is holding a physical ID with their own face on it. Reading the document, cross-checking the barcode against the printed text, confirming it is a card and not a screen, and matching its portrait to a live 3D face is the work. That is what the two dollars buys.
On purpose. A score reads as a warranty and turns you into the one who set the threshold. A reason code teaches an attacker which check to attack next. You get verified, failed or expired, we own the threshold, and the fine print says exactly what verified means.
Nothing that could identify the person survives 24 hours. There is no face index, no stored video and no template on file, so there is nothing to breach, subpoena or resell. The binding statement is our published Biometric Data Retention and Destruction Policy.
No, and that is the design. The images are destroyed once the check settles. What you receive is the result, the timestamp and your reference. If your process needs a human to look at a face, this is the wrong tool for that step.
There is no self-serve free tier. Tell us your use case and we will set you up with a test API key. Agents pay per call, so a first real check costs two dollars and needs no conversation at all.
Anyone who has to make an irreversible move on the word of a remote stranger: releasing escrowed funds, changing payment instructions, issuing a pickup or access credential, onboarding a seller or contractor. Increasingly that is an AI agent. ByteVerify is in early access. Tell us your use case and we will set you up with an API key or an x402 endpoint.

Add a checkpoint before the irreversible step.

One line for your agent. It reads the instructions, pays per check and reports back.

Send this to your agent
Read https://api.verify.bytefederal.com/skill.md and run a live face-to-ID check.

Human on the other end? Talk to us about an API key.

* The fine print

What a "verified" result does not tell you

  • That the ID is genuine or currently valid. We do not query DMV or issuer records. A format match is not proof of issuance.
  • Who the person is. No name, no database lookup, no identity resolution. We never learn it, so we never keep it.
  • Sanctions, watchlists, AML, KYC, credit or background. None of it. ByteVerify is not a screening service and must not be used for eligibility decisions.
  • That the person is authorized for your transaction. A match tells you a live person holds an ID with their face on it. Whether they may do what they are about to do is your control, not ours.

What "live and holding their own ID" means. A 3D liveness check passed, the live face matched the portrait on the document presented, and that document matched a recognized government-ID format. It is a determination about the scan, not about who the person is, and it is not a certification that anyone is human or unique.

Use it as one signal among several. ByteVerify is a supplemental risk signal. Keep it inside your own controls (account binding, device signals, limits, and confirmation through a channel you already trust) before you release funds or grant access on the strength of it. Never use the result for decisions about credit, insurance, employment or housing; that use is prohibited under our terms.

There is no score and no reason code, on purpose. A score would read as a warranty, and a reason code would tell a fraudster which check to attack next.

Statement of service

ByteVerify performs an on-demand live facial capture and face-to-government-ID photo comparison. It returns a limited result and deletes the facial and document inputs after processing. It does not, unless separately stated and supported by the applicable workflow, perform government-record validation, database identity resolution, sanctions or watchlist screening, AML/KYC screening, background checks, account-ownership verification, or authority verification, and it does not guarantee against fraud. Results must not be used for decisions covered by the Fair Credit Reporting Act.

The liveness and matching technology has been tested by NIST/NVLAP-accredited labs under ISO/IEC 30107-3 and ISO/IEC 19795-2. The figures on this page are as published by the technology's vendor and describe the technology, not an audit of ByteVerify's deployment. Facial and document data are processed on infrastructure Byte Federal operates and are destroyed on completion, no later than 24 hours, under our Biometric Data Retention and Destruction Policy.

Byte Federal, LLC is a licensed U.S. money services business. Price shown is the per-check price for x402 access, in USD, payable in USDC; every check is billed when created, including checks that expire unused. Volume pricing, rebates and enterprise terms for API-key customers are set by agreement.