The system of record for identity documents, and the shield that verifies them.
Aminata Registry Hub 360™ turns scanned Kenyan identity and company documents into a governed reference registry — then lets trusted service accounts verify a person or company against it in milliseconds, without ever exposing the source document.
- 7
- Document types
- HMAC
- Signed responses
- 100%
- Actions audited
- <1s
- Typical verify
Two actors. One governed pipeline.
Registry Administrators curate the truth. FraudShield service accounts consume it through a narrow, signed interface. Nothing crosses between them except an outcome.
Guided capture & extraction
A four-step wizard walks every document from type selection to activation, with vision OCR extracting each field and flagging low-confidence pages before anything is saved.
Individual registry
National ID, Passport, Alien ID and Personal KRA PIN references, normalised, masked and cross-checked front to back.
Company registry
Company KRA PIN, CR12 and CR13 with director and shareholder extraction, address normalisation and blocking validation.
FraudShield verification API
A signed machine-to-machine endpoint returning CONFIRMED, DETAILS_MISMATCH, NOT_FOUND or INACTIVE with per-field results — never the underlying document.
Immutable audit trail
Every retry, edit and verification is written once with old value, new value, actor and timestamp, then searchable and exportable.
Signed webhooks
Downstream systems receive HMAC-signed notifications the moment an outcome resolves, with a full delivery log.
From a scanned page to a signed verdict.
- 01
Capture
Administrator uploads front, back or multi-page reference documents into private storage.
- 02
Extract
Vision OCR reads every field, scores confidence and marks the source page.
- 03
Review
Side-by-side diff of extracted versus saved values, locked read-only on confirm.
- 04
Verify
FraudShield matches candidate details and returns a signed, per-field outcome.
Verify without ever handing over the document.
Service accounts authenticate with a client ID and secret, are constrained by IP allowlists and per-minute rate limits, and receive an HMAC-signed body they can independently verify. Identifiers come back masked; only the match result is disclosed.
- Client credentials with rotation and scoped environments
- Per-field matched / mismatched breakdown on every response
- Idempotency keys make duplicate submissions safe
- Every call persisted for compliance export
{
"document_type": "national_id",
"document_identifier": "********",
"candidate_fields": {
"full_name": "…",
"date_of_birth": "…"
}
}
→ 200 OK X-Aminata-Signature: sha256=…
{
"outcome": "CONFIRMED",
"document_identifier_masked": "3•••••21",
"field_results": [
{ "field": "full_name", "matched": true },
{ "field": "date_of_birth", "matched": true }
],
"correlation_id": "corr_…",
"processing_ms": 142
}Talk to us about your verification volume.
Tell us where you're verifying identities today and we'll set up a registry workspace and FraudShield service account scoped to your organisation.
- Sandbox client credentials for the verification API
- Guided onboarding for your first reference documents
- Signed webhook delivery into your existing systems
Ready to work the registry?
Sign in to the administrator portal to upload references, recover extractions and manage API clients.