Skip to content

ID Verification

Review the government ID photos your customers upload, approve or reject each request, and decide whether customers must be verified (KYC / age check / 18+) before they can withdraw cash or claim prizes. This page covers the decision queue, the gating settings, your accepted-documents policy, and what the customer experiences at each stage.

Where to find it: Admin → ID Verification (/admin/id-verifications)

How verification works

A customer uploads up to four photos of an ID document from their account page. The request lands in your queue as Pending. You open it, check the photos against the on-screen checklist and your accepted-documents policy, then Approve (the customer is marked as verified and 18+) or Reject with a reason (the customer sees the reason and can resubmit). Photos are automatically deleted three days after a decision — after that you can still see the request record, but not the images.

Every request carries one of four statuses:

StatusMeaning
PendingWaiting for a decision — appears in your default queue view.
ApprovedAn admin approved it; the customer is verified and 18+.
RejectedAn admin rejected it with a reason; the customer can submit again.
SupersededClosed without an approve/reject decision — either the request sat Pending for 30 days and expired automatically, or an admin revoked the customer's verified status from their user profile while the request was still open.

Check your review backlog

  • The Pending stats card at the top of the queue (alongside Approved, Rejected and Superseded counts) shows how many requests are waiting.
  • The ID Verification item in the admin sidebar carries an amber badge with the pending count, so you can see the backlog from anywhere in the admin area. It refreshes automatically every half-minute or so, and again whenever you move between admin pages.
  • To hear about new submissions without being in the admin area, the ID Verification Submitted event can send a push notification to your phone or a message to a private team channel — see Webhooks & Push Notifications. The alert only says a submission needs review; it never includes the documents.

Find and filter requests

The queue shows one row per request with its status badge, the customer's name and email, the number of photos (with a (purged) marker once images have been deleted), the submitted date, and — for decided requests — the decided date.

  1. Use the Status dropdown above the table to switch between Pending (the default), Approved, Rejected, Superseded, or All.
  2. The table shows 20 requests per page — use the pagination controls beneath it for older requests.
  3. Click Review (pending requests) or View (decided requests) to open the request in a side panel.
  4. Click the customer's name in the table to open their user profile panel directly.

Requests from customers who have since deleted their account stay in the queue, still showing the name and email captured at submission time — see Review a request from a deleted account.

Review and approve a request

  1. Click Review on a pending request. The panel opens with the customer's details, the request status, and the verification checklist — these load straight away.
  2. To see the ID photos you'll be prompted with Confirm to view ID images — enter the code from your authenticator app. This extra step protects the photos: every view is logged. If you cancel the prompt, the rest of the panel still works and a Try fetching images again link lets you retry.
  3. Compare the photos against the on-screen Verification checklist:
    • The document is genuine, in date, and matches the customer's name on file.
    • The date of birth on the document confirms the customer is 18 or older.
    • The photo is clear and not partially obscured.
  4. If you've published an accepted-documents policy, expand Operator policy — accepted documents in the panel to check the document type against your own rules. The platform doesn't enforce the policy — you compare against it at review time.
  5. Click a thumbnail to open the photo full size in a pop-up viewer — useful for reading dates of birth and expiry dates. Close it to return to the panel.
  6. Click Approve, then confirm in the Approve verification? dialog. No authenticator code is needed to approve — only viewing the photos requires one.

What happens next: the customer is marked as verified and 18+, their account page shows ID Verified, any withdrawal or prize-claim gate no longer applies to them, and the photos are purged three days after the decision. The queue and the pending count refresh automatically.

Note: photo links are short-lived. If you spend more than about five minutes on a single request, the thumbnails refetch automatically and you'll be asked for a fresh authenticator code.

Reject a request

  1. Open the request and click Reject.
  2. Pick a Rejection reason from the dropdown. The customer sees this exact wording in their account:
    • The photo is too blurry, dark, or partially obscured.
    • The document has expired or is no longer valid.
    • The name on the document doesn't match the account name.
    • The document indicates the holder is under 18.
    • Other (must include a note) — shown to the customer as "Please contact support for details."
  3. Optionally add an Admin note (up to 500 characters) — it's shown to the customer alongside the reason, so keep it factual and kind. For Other the note is required and should describe what needs to change, because the note is the only explanation the customer gets alongside the generic reason.
  4. Click Reject to submit, or Cancel to go back to the Approve/Reject choice without deciding.

What happens next: the customer's account page shows the rejection reason and your note with a Submit again button, so they can upload better photos. Rejection doesn't need a confirmation dialog or an authenticator code — it's recoverable, because the customer can always resubmit.

Look up a past decision

To see who decided a request and why:

  1. Switch the Status filter to Approved, Rejected, Superseded, or All.
  2. Click View on the request.
  3. The Status section shows the submitted date, the decided date, the email address of the admin who decided it, and — for rejections — the reason and any note.

Decided requests can't be re-decided from the panel; it simply notes "This request has already been decided." If a decision was wrong, ask the customer to submit again (after a rejection) or verify them manually (after a wrongful rejection) — see Verify a customer manually.

Jump to the customer's account

From the queue, click the customer's name in the table; from inside the review panel, click View user profile →. Either opens the customer's profile panel, where you can check their account details, orders and wallet before deciding. See Users for everything you can do from there.

Review a request from a deleted account

If the customer deleted their account after submitting, the request remains in the queue for your records. The row still shows their name and email — a snapshot taken at submission time — but the name is no longer clickable, and inside the panel the View user profile → link is replaced by the note "User account has been deleted; review snapshot only." There's no profile to open and no decision worth making; the record simply preserves what was submitted and decided.

Verify a customer manually

Sometimes you need to mark a customer as ID-verified outside the queue — for example, you verified them another way, or a request was rejected in error. From the customer's profile panel (see Users):

  • Quick verify — next to the ID Verified badge, click Verify ID (shown only while the customer is unverified and their account isn't archived). You'll be asked for your authenticator code, then the customer is marked as verified.
  • Edit mode — open the profile in edit mode and tick (or untick) the Verified (18+) checkbox under ID Verified. Saving prompts for your authenticator code. This is also the only way to revoke a customer's verified status.

If the customer had a pending request in the queue when you verified them manually, that request is automatically marked as Approved rather than left dangling. The reverse also applies: if you revoke a customer's verified status while they have a pending request, that request is closed as Superseded. Prefer the queue flow for normal reviews — it keeps the photos, reason and reviewer together in one record.

Gate withdrawals or prize claims

Two switches control whether unverified customers are blocked from money-out actions. Find them under Admin → Settings → Identity Verification:

  • Require ID verification before withdrawals — customers can't request a cash withdrawal until an admin approves their ID. Withdrawals already pending when you switch this on are not retroactively blocked. See Wallets & Withdrawals.
  • Require ID verification before prize claims — customers can't take a prize, take cash, or take credit on a winning ticket until approved. See Winners.

Each toggle saves immediately when you flip it — there's no separate save button. Both are independent, so you can gate withdrawals without gating prize claims (or vice versa).

Both switches start turned on on a newly created site, so customers have to verify before they can withdraw or claim a prize from day one. Turn either off if that doesn't suit how you run your site. Sites created earlier keep whatever they're set to now, so it's worth opening this screen once to check both switches say what you expect.

What the customer sees while a gate applies to them: a yellow Identity verification required banner on their Wallet page (withdrawals) or Prizes page (prize claims), explaining they need to verify before continuing and linking straight to the upload panel on their account page. The banner disappears as soon as they're approved.

Publish your accepted-documents policy

Tell customers which documents you accept (passport, driving licence, and so on) before they upload — it cuts down on rejections.

  1. Go to Admin → Settings → Identity Verification.
  2. In the Accepted documents box, write your policy in Markdown (a simple bulleted list works well). Up to 4,000 characters.
  3. Check the live Preview alongside the editor as you type.
  4. Click Save to publish, or Discard to throw away unsaved edits.

Your policy appears in two places:

  • For customers — a "What we accept" box on the upload panel on their account page.
  • For reviewers — a collapsible Operator policy — accepted documents section inside the review panel, so whoever is deciding can check submissions against the same list.

The platform doesn't enforce the policy automatically; your reviewer compares uploads against it at decision time.

What your customer experiences

The customer's side of verification lives in the ID Verification panel on their account page.

  • Before submitting — the panel invites them to upload up to four clear photos of an accepted document, shows your "What we accept" policy, and accepts JPG, PNG or HEIC files up to 10MB each (drag-and-drop or file picker on desktop, camera/photo picker on touch devices).
  • After submitting — the panel shows pending review with their submitted date and photo thumbnails, and tells them an admin will review shortly and that they'll get an email once a decision is made. They can't submit another request while one is pending, and repeated submissions in a short window are rate-limited.
  • On approval — the panel shows ID Verified: "Your identity has been verified. You're confirmed to be 18+ and eligible for all prize types." Any gate banners on Wallet and Prizes disappear.
  • On rejection — the panel shows needs another submission with the rejection reason and your admin note, plus a Submit again button to upload fresh photos.

Photo privacy and retention

  • ID photos are visible only to reviewing admins, and every photo view requires an authenticator code and is logged.
  • Photos are automatically deleted three days after a decision. The review panel then shows "Images purged on … (3-day retention)" and the queue marks the row (purged). Make any second look at the photos within that window — after it, only the request record (status, dates, decision, reason, note) remains.
  • The decision record itself is kept, including a snapshot of the customer's name and email, so your audit trail survives even photo deletion or account deletion.

Who can do what

  • Admin — full access: queue, photos, decisions, manual verification, and the Identity Verification settings.
  • Shop Manager — can work the queue: view requests and photos, approve, reject, and verify customers manually. The Settings area doesn't appear in their sidebar, so gates and the accepted-documents policy are Admin-managed.
  • Marketing — no access; the ID Verification item doesn't appear in their sidebar.

Troubleshooting

"This request was already decided by another admin." — Two people had the same request open and the other one decided first. The panel closes and the queue refreshes automatically; check the request under its new status if you want to see what was decided.

The photos won't load / I cancelled the code prompt. — The panel shows "Step-up auth was cancelled" with a Try fetching images again link. Click it and enter a fresh authenticator code. The same link appears if the code you entered was invalid or the fetch failed.

The thumbnails went blank mid-review. — Photo links expire after about five minutes. The panel refetches them automatically and prompts you for a new authenticator code — enter it and carry on.

I opened an old request and there are no photos. — If the panel says "Images purged", the three-day retention window has passed. The photos are gone permanently; rely on the recorded decision, reason and note instead.

A customer says they can't submit again. — They can only have one request open at a time. If their last request is still Pending, decide it first — the moment you reject it they get a Submit again button; if you approve it there's nothing more for them to do.

A customer says they can't withdraw or claim a prize. — Check whether the relevant gate is on under Settings → Identity Verification and whether the customer is verified (their profile shows an ID Verified badge — see Users). If the gate is on and they're unverified, they'll see the verification banner until a request of theirs is approved.

The document shows the customer is under 18. — Reject with "The document indicates the holder is under 18." Consider whether the account needs further action — see Responsible Play and Users.