Gate devices and the SDK
Run face check-in at the door — offline, 1:1 against the scanned ticket, with liveness checks.
Gates run the FacePing SDK. Each device holds an encrypted copy of one event's face templates and checks guests on the device itself: no network needed at the door, and no face data leaves the device.
1. Give each gate a device token#
Never put an API key on a gate device. Create a device token instead — read-only, for one event, and it expires with the event's retention. In Dashboard → event → Gate devices, or:
POST /v1/events/{eventId}/device-tokens →
Lost a device? Revoke its token: it wipes its copy at its next sync.
DELETE /v1/events/{eventId}/device-tokens/{tokenId} →
2. Add the SDK (.NET MAUI)#
The MAUI SDK runs on Android 7.0+ and iOS 15+. Native Swift, Kotlin, Flutter and React Native SDKs follow the same design.
// MauiProgram.cs
builder.UseFacePing(o => o.ApiBaseUrl = new("https://api-eu.faceping.ai/"));
3. Sync, then check guests#
var gate = await gateFactory.CreateAsync(eventId, deviceToken); // FacePingGateFactory, injected
await gate.SyncAsync(); // auto-sync then runs every 5 minutes
using var session = await gate.OpenAsync(); // works offline from here
// For each guest: scan the ticket, then feed live camera frames.
var attempt = session!.BeginAttempt(scannedTicket);
var orienter = new FrameOrienter(await models.PipelineAsync()); // FacePingModels, injected; frames arrive sideways
while (attempt.State == GateAttemptState.Pending)
{
ShowPrompt(attempt.Prompt); // LookAtCamera / TurnLeft / TurnRight / LookBack
attempt.Feed(orienter.Upright(MauiFrames.FromPlatformImage(frame)!));
}
| Result | What to do |
|---|---|
Admitted |
Open the gate |
NotEnrolled, LeaseExpired, Closed, Expired |
Standard (non-face) lane |
LivenessFailed, ChallengeFailed, NoMatch, NoFace |
Staffed lane |
Anti-spoofing#
BeginAttempt applies FacePing's gate policy for you:
- Passive liveness on every frame (score ≥ 0.9) — one frame that looks like a photo or screen ends the attempt.
- Active liveness: after a live frontal match, the guest turns their head in a random direction, then looks back for a second match. Any wrong-way turn fails.
- 10-second window, then the staffed lane.
These defeat photos and screens. A replayed video of the guest could beat the head turn; for unattended gates, run face lanes with staff in view.
Offline and withdrawal#
- Packs are AES-256-GCM encrypted with a per-event key held in the device keychain/keystore.
- A device that can't reach FacePing keeps working for 24 hours (its lease), then stops verifying until it syncs.
- Revoking a device, deleting the event or suspending your account wipes devices at their next sync.
- At the retention deadline the device deletes the key first, then the data — even offline.