Offline face verification SDK

Verify faces.
Even offline.

Built for
apps
Tap to pick yours

Face verification that runs on the phone, works with no signal and has liveness built in. Add it to an app you already build in about 10 minutes.

Free sandbox keyNo cardRust core

Running events or ticketing? Try the server side in the sandbox (check-in lists, enrolment links, the widget and devices), or .

Pick your platform to see the code

Under 0.3 sper check, on the phone
Airplane modechecks need no network at all
Liveness built inphoto and screen spoofs refused
£0 per checkpay per person stored, not per check
For developers

Ten lines to your first face match.

Same idea on every platform: enrol a face once, verify it whenever you like, with or without a connection.

MauiProgram.cs + MainPage.xaml.csAvailable in preview
// MauiProgram.cs
builder.UseFacePing(o => o.SandboxKey = "fp_test_…");
// The first run needs a connection: the SDK activates your key itself (no sync call needed).

// MainPage.xaml.cs: faceping is the injected IFacePing; Camera is a <fp:FaceCameraView>
// Add the face once, on the device
await faceping.EnrollAsync("me", await Camera.CaptureAsync());

// Verify any time, with no network (live, with a head turn)
var result = await faceping.VerifyLiveAsync("me", Camera);

// result.Outcome        → Match
// result.LivenessScore  → 0.98
// result.Elapsed        → 1.7 s
1
Turn it onOne package and your free sandbox key.
2
Enrol a faceOne photo, with the person's consent.
3
Verify, offlineA live check, head turn included, takes under two seconds. Each face check is under 0.3 s.
Follow the MAUI guide Or clone the finished MAUI app on GitHub
How it works

Enrol once. Check anywhere.

Your app holds an encrypted copy of the faces it needs, so every check runs on the device.

Step 1 · Enrol

One photo, with consent

The person agrees and takes a selfie. In the sandbox, on the device or on a practice list through our widget, your server or the dashboard's front desk; in production, through our widget, your server or your front desk.

Step 2 · Sync

An encrypted pack per device

Devices download only the faces they need, locked with their own key. A device that loses access wipes itself.

Step 3 · Verify

Offline, against the right person

Scan a ticket, card or ID, then look at the camera. FacePing confirms it's that person, and that they're really there.

Under the hood

One face engine, built in Rust.

Detection, liveness, matching and encrypted storage all run in the FacePing core: memory safe, compiled, and the same on every phone and our servers.

Memory safe

Rust rules out whole classes of bugs, such as buffer overflows, in the code that reads images.

Compiled native code

The matching and liveness logic is compiled native code, not readable .NET or JavaScript.

One engine everywhere

The same core on the phone and on our servers. .NET MAUI, Avalonia, Android, iOS, Flutter, React Native and Capacitor, all thin layers over the same core.

Encrypted at rest

Face templates are sealed with AES-256-GCM, with the key in the Keychain or Keystore.

How we protect face data

Why FacePing

Finding a face is free. Knowing whose face it is isn't.

ML Kit and Apple Vision find faces but can't tell you who they are. Cloud APIs can, but need a connection for every check.

FeatureFacePingCloud face APIsML Kit / Apple Vision
Tells you whose face it isYesYesNo, detection only
Works with no networkYesNoYes
Liveness and anti-spoofingBuilt inVaries, often extraNo
Cost per check£0About £0.001 eachFree
Consent and deletion toolingBuilt inBuild it yourselfBuild it yourself
Use cases

Anywhere you need to know it's the right person.

Events and ticketing

Faster entry and no ticket touting. Verify against the scanned ticket, then delete everything after the event.

Gyms and memberships

No shared cards. Members walk in with their face, even when the Wi-Fi is down.

Staff clock-in

No buddy punching. Clock in on a shared tablet on site, with or without a connection.

Kiosks and check-in

Self-service check-in without a card. Searching all faces (1:N) is available once we approve your use case.

Privacy by design

Verification, not surveillance.

FacePing checks that a person is who they say they are, with their consent. It isn't built to identify strangers, and we won't let it be used that way.

Read how we handle data
  • Consent built inA clear question, with an equally easy “no thanks”.
  • No photos keptThe photo becomes a face template, then it's gone.
  • Deleted on scheduleOn our servers and every device, with a log to prove it.
  • Your regionHosted in the EU. UK and US regions on request.
  • Paperwork includedDPA, DPIA template, privacy notice and consent wording.
  • Checked before go-liveThe sandbox is instant. Production needs one quick review.
Pricing

The price is right here.

You pay for each person stored with FacePing in a month. Checks and devices are unlimited, and so are check-in lists on paid plans (the free pilot has one).

SandboxInstant
£0 for testing
  • 25 faces per device or practice list
  • Each deleted after 24 hours
  • No card, no approval
Get a sandbox key
Pay as you go
3p per person / month
  • No monthly fee
  • Only the people you store
  • Invoiced monthly
Choose Pay as you go
GrowthPopular
£99 / month
  • 5,000 people a month included
  • Then 2p per person
  • Email support
Choose Growth
Scale
£399 / month
  • 30,000 people a month included
  • Then 1p per person
  • Priority support
Choose Scale
Free 30-day pilot when you go live (up to 500 people, one list)Unlimited checks and devices, and unlimited lists on paid plansNo setup feeCancel any time

A person counts once in a month if their face is stored at the end of it, or was enrolled and deleted within it. Prices exclude VAT. Prices in pounds, euros or US dollars: you pay in the currency of the data region you choose when you go live. Larger volumes or custom terms: . How billing works.

Questions

Good to know

Is it really offline?

Yes. Once a device has synced, every check runs on the phone or tablet: no network, no cloud call. Devices sync again to get new enrolments and stay authorised: a production device keeps working offline for 24 hours (its lease), and a sandbox app for 30 days after its key was last activated or renewed.

Why do I have to apply before going live?

Face templates are biometric data under GDPR and several US state laws. We check your use case once, usually within two working days. The sandbox needs no approval, so you can build your app while we review. You can try the server side too: your sandbox key works on the API on one practice check-in list, with enrolment links, the widget and check-in devices (up to 25 people, each face deleted after 24 hours). Going live lifts the limits for real people.

We sell tickets. How does 1:1 work with them?

Each ticket gets its own face: the person enrols against their ticket number, and at the door the device checks the face in front of it against that ticket only. FacePing doesn't stop one person enrolling on several tickets (one face per ticket, not one ticket per face), and it never searches other tickets for a match. It answers one question: is this the person who enrolled for this ticket?

How does billing work?

You pay for each person stored with FacePing in a month. A person counts if their face is still stored at the end of the month, or if they were enrolled and deleted within it, and nobody counts twice in a month. Your billing month runs from the day your paid plan started. So a one-day event whose faces are deleted 10 days later counts each person once, and a gym member counts every month they're enrolled. Checks, devices and failed attempts never count. Prices exclude VAT, in the currency of the data region you choose when you go live: pounds for the UK, euros for the EU, US dollars for the US.

Can it search a crowd for someone?

No. FacePing isn't built for surveillance: it only recognises people who enrolled themselves with consent. By default it checks each person against their own face (1:1). For an opt-in kiosk, where people walk up without a ticket, it can match against everyone enrolled on that list (1:N), once we've approved the use case.

Which platforms are supported?

.NET MAUI, Avalonia, iOS (Swift), Android (Kotlin), Flutter, React Native and Capacitor, all available now as previews. Each has a step-by-step guide and a finished starter app on GitHub.

How secure is it?

The face engine is written in Rust, a memory-safe language, and ships as compiled native code. Face templates are encrypted on the device, checks never leave the phone, and any device can be revoked, wiping its copy at its next sync. The detail is on our security page.

Where is face data stored?

On the device, encrypted with AES-256-GCM, and on our servers in the EU (UK and US regions on request). It's deleted on the schedule you set, and every deletion is logged.

From empty project to a face match in about 10 minutes.

If you already build mobile apps: pick your platform, get a free sandbox key, follow the steps.