Prompt
How do I handle identity verification retries when selfie match fails?
Latest observation
Oct 4, 2026
OpenAI APIWeb search: off
When a selfie match fails, the goal is to let the user retry safely without creating a bad experience or weakening fraud controls. A good retry flow usually includes:
-
Give a clear reason
- Tell the user the match didn’t pass, without exposing sensitive scoring details.
- Example: “We couldn’t verify that the selfie matches the ID.”
-
Allow a limited number of retries
- Common practice is 2–3 attempts before pausing the flow.
- Too many retries can indicate fraud or poor capture quality.
-
Offer guidance before retrying
- Ask for better lighting
- Remove glasses, hats, masks if allowed
- Center the face
- Use the same person as the ID
- Ensure the ID photo is clear and unexpired
-
Differentiate retry types
- Instant retry for likely capture issues
- Manual review after repeated failures
- Fallback verification such as document re-upload, liveness retry, or alternate ID method
-
Track retry state
- Store the number of attempts and timestamps
- Enforce cooldowns if needed
- Prevent unlimited retries in the same session
-
Preserve security
- Don’t allow the user to bypass verification after a failure
- Use risk rules to escalate repeated failures
- Monitor for device/IP/account patterns suggesting abuse
-
Make the UX reassuring
- Explain that failures can happen due to image quality
- Keep the user in the flow with a prominent retry button
- Avoid blaming language
Example retry message:
“The selfie didn’t match your ID. Please try again in better lighting and make sure your face is fully visible. You have 2 more attempts.”
If you want, I can also provide:
- a retry policy template
- a sample API/state machine design
- or code for a retry flow in your stack.