AllowID developers

Work in progress. The API and SDKs work today, but AllowID is still being built: details may change before a first stable release.

Any QR reader

A person opens the AllowID app and shows its QR code. Whatever reads it sends the text to AllowID, and gets back who it is.

What counts as a reader§

Anything that turns a QR code into text:

The app's QR code is ordinary text. It starts with PI, followed by ten letters and digits, and sometimes more after a colon (a signature the app adds). Send all of it as it was read; you don't need to parse it.

The call§

answer = client.scan(text)

if answer.result == "resolved":
    person = answer.subject          # same for this person every visit, at your company
    if answer.linked:
        email = answer.claims["email"]

The answer§

resultMeaningBilled
resolvedA current AllowID code. subject says who.yes
unknownLooks like one but is not current: a screenshot from earlier, an expired code, a revoked phone.no
invalidNot an AllowID QR code at all, such as a product barcode.no
replayedThis exact code was already used: here more than a minute ago, or at another company.no

The same code again from your company within a minute (a reader that reads twice, a person who holds the phone too long) returns the first answer with repeat: true and is not billed again.

The code in the app changes every 30 seconds, and AllowID accepts it for about a minute and a half. Send it when you read it. Don't queue it to send later.

A complete reader program§

For a keyboard-style USB scanner: read a line, ignore anything that is not an AllowID code, ask AllowID, act on the answer. The shape check runs locally, so a product barcode costs nothing.

import sys
import allowid

client = allowid.Client()
known = {}                                   # subject -> name, in your own database

for line in sys.stdin:                       # the scanner types a line per QR code
    text = line.strip()
    if not allowid.is_allowid_code(text):
        continue
    try:
        answer = client.scan(text)
    except allowid.AllowIDError as e:
        print("AllowID unavailable:", e.code)
        continue
    if answer.result != "resolved":
        print("Not accepted:", answer.result)
    elif answer.subject in known:
        print("Welcome back,", known[answer.subject])
    else:
        print("New visitor", answer.subject)

Knowing who someone is§

A scan tells you which person it is (the subject), but not their name or email, unless that person has once approved your company in the app. The usual pattern:

  1. First visit: the person signs in once with the app, on your website or on a tablet at the desk (website sign-in). They see your company's name and approve sharing their email. You store the subject you get back against your own record of them.
  2. Every visit after: a scan returns the same subject, so you know who it is. It also carries linked: true and their email.

If you only need to recognise returning people (counting visits, unlocking a locker someone opened earlier), the subject alone is enough and step 1 is not needed.

When the network is down§

The API needs to reach AllowID: a scan cannot be checked offline. Decide what your door or desk does when network_error comes back. For a door, a fallback such as a receptionist or a badge is usually better than letting everyone in. AllowID's own access controllers can check the app's QR code offline for up to 24 hours. If you need that, ask us about an AllowID site controller.