AllowID developers

Work in progress. The API and SDKs work today, but AllowID is still being built: details may change before a first stable release.

Privacy and security

The AllowID app belongs to the person carrying it. The API is built so that showing it to your reader reveals as little as your purpose needs.

One identifier per company§

The subject you receive is computed for your company. The same person has a different subject at every other company, so two companies comparing their records cannot tell they saw the same person. It is stable for as long as the person keeps their AllowID account, and it is not a secret: store it like any user id.

A scan tells you that it is the same person as before. It tells you who only once the person has signed in to your company with the app. On that screen they saw your company's name, your purpose and each attribute you asked for, and approved. Email is always shared on sign-in; every other attribute is off until they turn it on. After that, scans at your company carry the same email and attributes.

A code works once§

The QR code in the app changes every 30 seconds and is accepted for about a minute and a half. Each code is answered once across all of AllowID: a code read at your reader cannot be replayed at another company, and a screenshot is worthless shortly after it was taken.

Keeping your key safe§

What AllowID keeps§

Each request made with your key: company, key, kind, result, time90 days
Billed answers (for invoicing)400 days
A scanned code, to answer it only once5 minutes
Which people approved your companyuntil the person deletes their AllowID account

AllowID does not keep the codes your readers send, nor what you do with the answer. Keys are stored as SHA-256 hashes. The service runs in the EU (Frankfurt).

Your responsibilities§

What you store about a person (their subject, email and visits) is your data, under your privacy policy. Tell people that you use AllowID to recognise them, and keep only what you need.