One face. One GUID. Forever.
Read three digits aloud. FaceGUID checks that the right digits were spoken and that the mouth on camera actually articulated them, then hands you a permanent identifier bound to your face. Come back on any device, any browser, any year — same face, same GUID.
The same GUID, on the other side of the API
What you get in one click, an organisation gets as a signed assertion: a live human was here, and it is the same human as last time. No image, no video, no descriptor ever reaches them — only a UUID and a signature they can verify.
One call in the browser
A script tag and fg.proveHuman(). FaceGUID opens the camera on this origin,
so the site never asks for camera permission and never touches biometrics.
One call on their server
A POST with their client secret turns the token into human: true, a stable
subject, and how long you have had a FaceGUID. Each proof is spendable once.
One human, one account
Because the identifier comes from the face, a second account needs a second face. Sybil resistance stops being a guess and becomes a property.
How the check works
Four things have to line up at once. Fail any one and no key is produced.
The digits come from the server
Three random digits, issued per attempt, valid for two minutes, burned on first use. A recording of you saying yesterday’s digits is worth nothing.
Your lips have to say them
Lip-aspect ratio is tracked against your own silent baseline. Open-close articulation cycles must actually occur — a still photo produces none.
Voice and lips have to match
Microphone energy and mouth opening are cross-correlated with lag tolerance. Audio played from a phone next to a photo desynchronises immediately.
The face cannot change mid-check
A descriptor is taken before the challenge and again after, and every capture frame is compared to it. Swap faces halfway and the ceremony aborts.
Where the key actually comes from
A face is fuzzy; a key must be exact. FaceGUID bridges that with a fuzzy commitment over reliably-selected projections: at enrolment the browser finds the 1,920 random projections of your face descriptor that stay most stable across frames, binds a random 128-bit secret to their sign bits with a repetition code, and stores only the XOR mask. Later, a fresh scan majority-decodes the same secret back out — even though the descriptor is never identical twice.
That secret never leaves your browser and is never stored anywhere. It is what unwraps your vault master key and your signing key. The server holds the mask, which without your face is noise. The full model →