AllowID developers

Work in progress. The API and SDKs work today, but AllowID is still being built: details may change before a first stable release.

Pricing, limits, errors

You pay for answers, not for requests. The first 1,000 every month are free.

What counts§

Billed
A scan AllowID recognised (resolved)yes, 1
A sign-in the person approved, the first time your server collects ityes, 1
The same code again within a minute (repeat)no
Codes that are unknown, invalid or replayedno
Starting a sign-in, checking its status, collecting it againno
A sign-in nobody approved, or one that was declinedno
usage, healthno

The allowance§

The company console shows the month so far under API, and every billed answer carries usage, so your own software can watch it too.

Usage emails§

The owners and administrators of your company get an email when the month reaches 80 % of the allowance, at 100 % (grace starts), and at 120 % (the API pauses). One each per month. The mail holds your company name, the numbers and a link to the console. Nothing about who scanned.

Rate limits§

1,200 requests a minute per key; above that, rate_limited (HTTP 429) with Retry-After: 60. A busy site with several readers can use one key per reader to stay well clear.

Error codes§

codeHTTPWhat to do
missing_key401 / —Set ALLOWID_API_KEY where the code runs.
invalid_key401The key is mistyped or was revoked. Make a new one in the console.
rate_limited429Wait a minute; spread readers over several keys.
quota_exceeded429The month's allowance and grace are used. usage says by how much.
invalid_request400Read detail, for example an unknown attribute name.
not_found404No such session for your company.
network_error—Raised by the SDKs when AllowID could not be reached. Decide what your door does then.
internal_error500Ours. Retry once; if it persists, send us the X-Request-Id.