Modules are the primary building blocks of Workflows and Flows. They allow you to collect selfies, documents, consent, or information from users. Each module is a part of the identity verification (IDV) process. In Workflows, some modules are considered Processes. Processes are prebuilt steps for validating data, identity checks, and fraud signals. Some modules have prerequisites that must be configured before they can be used. Refer to each module's documentation page for specific requirements.
You can configure modules as a part of Workflows or Flows directly in Dashboard or in the code of your SDK. We recommend using Dashboard for configuration, then calling to the Workflow/Flow ID from the SDK.
Depending on your organization's configuration, you may not see all possible modules. Contact your Incode representative if you have questions about the modules available in your organization.
The following tables can help you choose which modules to use. They are divided by category.
Collect Identity Data
These modules gather raw inputs from users. No pass/fail determination is made; these modules receive and record.
| Module | Description |
|---|---|
| Custom Fields | Captures additional user-provided data and saves it to the Session, making it available for reporting, server-side decisions, or cross-checking later in the journey. This module is deprecated. |
| Document Capture | Captures a supplementary document, such as a proof of address document, medical document, or bank statement. Users can upload a file or take a photo of the document with their device’s camera. |
| Email Input | Collects a user's email address and can confirm email ownership by sending a one-time password (OTP) to that address. |
| Face Capture | Captures a user’s face with their device’s camera and runs configurable liveness, face recognition, and image quality checks. It can enroll new users so their face can be matched against an ID photo or used for later authentication. It can also log in returning users using 1:1 or 1:N face authentication. |
| Face Onboarding | Allows a user to begin or resume Onboarding using face recognition, reusing their data from a previous Session with their consent. This reduces friction for returning users. |
| Fiscal QR OCR | Scans the QR code on a Constancia de Situación Fiscal, the SAT tax document issued in Mexico, and extracts the associated fiscal data. |
| Forms and Data Entry | Presents one or more custom form screens to collect information from a user. |
| Geolocation | Requests location permission, then captures the precise physical location of the user's device, using its GPS sensor to record coordinates and location fields such as country, state, and city. |
| ID Capture | Captures the front and back of a government-issued ID, with auto-capture and quality checks, and produces clean images for processing. |
| NFC Scan | Reads the secure NFC chip embedded in ICAO 9303-compliant travel documents, such as e-passports. It then returns the document holder's data, including the chip's portrait image. |
| Phone Number Input | Collects a user's phone number and can confirm phone ownership by sending a one-time password (OTP) via SMS. |
| Proof of Address Capture | Captures a proof-of-address document, such as a utility bill, bank statement, or telecom agreement, as an image or PDF. It then extracts the address data through OCR to validate the user's residential address. |
| Review OCR Data | Extracts text from a captured identity document using Optical Character Recognition (OCR). It then shows that text to the user to confirm it's correct before the session continues. When enabled, users can correct missing or misread fields. |
| Video Selfie | Records a short video of the user performing a guided series of actions, including capturing their ID and selfie, to confirm physical presence and run liveness and face match checks. It can also capture voice consent. |
Verify and Authenticate
These modules run checks against collected data to produce a pass/fail or match/no-match determination.
| Module | Description |
|---|---|
| Antifraud Check | Compares the current Session against prior Sessions and known identities to detect signs of fraud. |
| Claims Matching | Verifies an employee's identity by comparing data from their Session against trusted reference data from one or more connected directories. Sessions that fail are routed to manual evaluation. |
| Cross Check | Compares a data field from one source against the same field from a second source and identifies whether the values match. |
| CURP Validation | Validates a person's CURP (Clave Única de Registro de Población), a personal identification number issued in Mexico, against Mexico's RENAPO registry. It accepts a CURP extracted via OCR, entered manually, or generated from personal data when the user doesn't know it. |
| Custom Watchlist | Screens the user's collected data, including biometric face data when available, against your organization's private watchlist of blocked or trusted users, and influences the Session outcome accordingly. It runs as a background process and isn't visible to the end user. |
| eKYB (electronic Know Your Business) | Collects and verifies a business entity's identity data, such as business name, address, and tax ID. |
| eKYC (electronic Know Your Customer) | Collects and verifies a user's personal identity data against authoritative data sources. This data can include the user's name, email, address, phone, tax ID, date of birth, and nationality. |
| Face Authentication | Captures a returning user's face with their device’s camera and matches it against the face already enrolled for that user. It then returns a pass or fail result. |
| Face Login | Performs face authentication to allow users to log in without a password or token. |
| Face Match | Compares the user's selfie against their ID photo, their NFC chip photo, or both in a 3-way match. It then returns a confidence score. |
| Field Comparison | Compares fields from different sources, such as OCR data extracted from an ID and information entered by the user, to verify they match. It supports branching, so you can route users down separate paths depending on whether the comparison passes or fails. |
| Government Data Verification | Validates identity data extracted from a user's ID against an authoritative government registry. The process runs in the background and isn't visible to the user. |
| Government Record Verification | Verifies a person's identity by comparing identity attributes and, where supported, a live selfie against government-held records, producing a match or no-match outcome. |
| ID Validation | Determines whether a submitted identity document is authentic. It analyzes the images captured by the ID Capture module against known parameters for the document type, runs a set of authenticity checks, and produces a validation result. |
| Instant BAV | Validates a user's bank account information by checking key details such as name, address, account ID, and balance. |
| Risk AI Agent | Adds Risk AI Agent, Incode's intelligent fraud decisioning system, to a verification session. It evaluates signals from across the session and produces a more accurate pass/fail decision than set thresholds or custom rules. |
| Trust Graph | Connects to a cross-organization fraud intelligence network that links isolated sessions into a connected graph to detect fraud patterns without sharing Personally Identifiable Information (PII). |
| Watchlist | Screens the user's identity against sources of sanctions, Politically Exposed Persons (PEP) databases, and adverse media, returning any matches found across the configured sources. |
| Watchlist Business | Screens business entities against global sanctions lists, Politically Exposed Persons (PEP) databases, and adverse media, returning any matches found across the configured sources. |
Capture Signatures and Consent
These modules capture legally binding signatures and record user consent.
| Module | Description |
|---|---|
| Advanced Electronic Signature | Shows the user documents to sign, collects their consent, and captures a certificate-backed electronic signature. That digital certificate verifies their identity, making the signed document legally binding and compliant. |
| Certificate Issuance | Issues a digital certificate tied to a verified identity, supporting legally binding and compliant document signing. |
| Data Sharing Consent | Shows the user one or more preconfigured consents to review and accept, then records their agreement. Consents obtain the user's permission to collect and process their data. Most jurisdictions require this at the start of an identity verification journey. |
| Electronic Signature | Captures a signature the user hand-draws on screen. It is typically placed at the end of a verification journey to capture explicit consent. |
| Qualified Electronic Signature | Shows the user documents to sign, collects their consent, and captures a Qualified Electronic Signature (QES), the highest-assurance electronic signature under the EU eIDAS Regulation. A qualified certificate from a Qualified Trust Service Provider (QTSP) backs the signature, making it legally equivalent to a handwritten signature across EU member states. |
Add Human-Assisted Verification
These modules introduce a live agent into the IDV process.
| Module | Description |
|---|---|
| Video Conference | Connects the user with a live agent over video and audio to conduct an identity verification interview. The agent can request that documents be shown on camera and complete any verifications needed to meet regulatory or business requirements. |
Configure the User Experience
These modules shape the user experience of a Workflow or Flow, including routing decisions. They do not collect or verify data.
| Module | Description |
|---|---|
| Custom Module | Pauses a Workflow and hands control to your application, which runs custom logic and returns a result that determines how the Workflow continues. |
| External Decision | Calls a configured external endpoint and exposes the returned decision value for routing Conditions. |