FaceGUID
Biometric identifier

One face. One GUID. Forever.

Read three digits aloud. FaceGUID checks that the right digits were spoken and that the mouth on camera actually articulated them, then hands you a permanent identifier bound to your face. Come back on any device, any browser, any year — same face, same GUID.

Speak-to-verify liveness Server-issued challenge Key derived in your browser Proof-of-human API OpenID Connect for business
Camera idle
Camera and microphone stay on this device. Only a 128-number face descriptor — not an image — is ever sent, and only to match you against existing identities.
Your FaceGUID
Pass the spoken-digit check and your GUID appears here, ready to copy.
What you can do with it
Paste it anywhere.
A plain UUID. Put it in a profile, a support ticket, a smart contract, a business card.
Link your accounts.
Bind an email, a mobile number, and social URLs to this face — each one verified, each one revocable. Linked accounts →
Seal documents to your face.
A deed, a contract, a will. Encrypted in your browser, signed by your face key, kept forever — and provable to anyone without handing over the file. Seal a document →
Lock secrets to your face.
Passwords, recovery codes, API keys — encrypted in your browser, signed by your face key, searchable while encrypted. Open the vault →
Prove you are human, anywhere.
Sites that have integrated FaceGUID can ask you for a signed proof — you stay anonymous to them, and they learn you are a person rather than a script. How it works →
Let people log in with it.
Drop FaceGUID into your product as an OpenID Connect provider, or as a one-call proof-of-human check. Read the API →

The same GUID, on the other side of the API

What you get in one click, an organisation gets as a signed assertion: a live human was here, and it is the same human as last time. No image, no video, no descriptor ever reaches them — only a UUID and a signature they can verify.

One call in the browser

A script tag and fg.proveHuman(). FaceGUID opens the camera on this origin, so the site never asks for camera permission and never touches biometrics.

The SDK →

One call on their server

A POST with their client secret turns the token into human: true, a stable subject, and how long you have had a FaceGUID. Each proof is spendable once.

The API →

One human, one account

Because the identifier comes from the face, a second account needs a second face. Sybil resistance stops being a guess and becomes a property.

For organisations →

How the check works

Four things have to line up at once. Fail any one and no key is produced.

The digits come from the server

Three random digits, issued per attempt, valid for two minutes, burned on first use. A recording of you saying yesterday’s digits is worth nothing.

Your lips have to say them

Lip-aspect ratio is tracked against your own silent baseline. Open-close articulation cycles must actually occur — a still photo produces none.

Voice and lips have to match

Microphone energy and mouth opening are cross-correlated with lag tolerance. Audio played from a phone next to a photo desynchronises immediately.

The face cannot change mid-check

A descriptor is taken before the challenge and again after, and every capture frame is compared to it. Swap faces halfway and the ceremony aborts.

Where the key actually comes from

A face is fuzzy; a key must be exact. FaceGUID bridges that with a fuzzy commitment over reliably-selected projections: at enrolment the browser finds the 1,920 random projections of your face descriptor that stay most stable across frames, binds a random 128-bit secret to their sign bits with a repetition code, and stores only the XOR mask. Later, a fresh scan majority-decodes the same secret back out — even though the descriptor is never identical twice.

That secret never leaves your browser and is never stored anywhere. It is what unwraps your vault master key and your signing key. The server holds the mask, which without your face is noise. The full model →