This Addendum governs your use of Nyota ID, automated Know-Your-Customer (KYC), corporate Know-Your-Business (KYB), 3D passive liveness detection, and identity verification session APIs. This document forms an integral part of the Nyota Imara Master Terms of Service.
Effective Date: September 15, 2026
Parent Agreement: Master Terms of Service
Governing Jurisdiction: Republic of Kenya
This Nyota ID Product Terms & Verification Addendum ("ID Addendum") is an explicit, binding extension of the Nyota Imara Master Terms of Service ("Master Terms"). This Addendum applies to all customers, developers, financial institutions, SACCOs, and enterprise workspaces accessing or integrating the Nyota ID Verification API (POST /v1/verify/sessions), Web/Mobile SDKs (@nyota/verify-web-sdk), or Hosted Web Verification flows (verify.nyotaimara.com).
By creating a verification session or generating Nyota ID API keys, you agree to this Addendum, the Master Terms, and our Privacy Policy.
Nyota ID operates as an integrated B2B identity verification orchestrator and reseller utilizing the Didit V3 Protocol API (Didit Identity Ltd, European Union) for document OCR extraction, AML sanctions database screening, and 3D passive biometric liveness verification.
By using Nyota ID, you acknowledge and consent to the transmission of end-user verification payloads to Didit for real-time verification processing under strict European Union GDPR and Kenya Data Protection Act (2019) compliance standards.
Nyota Imara utilizes the exact same Nyota ID verification pipeline internally to process workspace owner KYC and corporate KYB onboarding across the Nyota ecosystem.
Nyota ID operates on a transparent, pay-as-you-go unit price model:
When your application calls POST /v1/verify/sessions to initiate a verification flow, Nyota ID places an immediate credit hold (reservedCents) on your workspace Nyota Wallet for the exact cost of the check.
Final debit (finalizeVerificationDebit) occurs only when Didit returns an authenticated verified (Approved) verdict callback.
If a verification session is declined (e.g., photo mismatch, fraudulent ID document, failed liveness), abandoned by the user prior to completion, or expired (session timeout after 24 hours):
An automated background sweeper runs hourly to evaluate pending verification sessions. Any session remaining in an uncommitted state for more than 24 hours without a terminal callback is automatically expired and its wallet hold is released.
Nyota Imara operates in strict compliance with the Kenya Data Protection Act (2019) and regulations enforced by the Office of the Data Protection Commissioner (ODPC).
B2B clients integrating Nyota ID via SDKs or APIs warrant and represent that they have obtained prior, explicit, informed consent from their end-users to collect, process, and transmit identity documents and biometric liveness media prior to initiating a verification session.
Nyota Imara does not permanently store or retain raw biometric 3D facial vector meshes or unencrypted identity document images in primary relational databases. Biometric liveness frames are processed ephemerally during active session execution.
Following session execution, Nyota Imara persists only:
Secret API keys prefixed with ny_live_... or ny_test_... must be strictly restricted to server-to-server requests. You shall not expose master API keys in client-side JavaScript, public web repositories, or compiled mobile application binaries. Client applications must interact exclusively via short-lived verification session tokens issued by your backend.
Developers integrating Nyota ID must not rely solely on client-side SDK UI callbacks to grant access, approve loans, or update user state in production databases.
Your backend server is strictly required to verify the HMAC-SHA256 signature (X-Nyota-Signature) on incoming verification.completed webhook payloads before acting on a verification decision.
While Nyota ID provides industry-standard 3D passive liveness detection and government registry document validation, Nyota Imara does not guarantee that an approved user will not commit offline fraud, breach of contract, or illegal acts.
Nyota ID provides verification technology to assist your compliance workflows, but your organization remains solely responsible for its own credit underwriting, risk management, and business decisions.
Inquiries regarding identity data processing, ODPC compliance audits, or custom enterprise volume pricing (>2,500 checks/month) should be directed to: