BlinkID Verify 4000.0.0
Release date: October 9, 2026
What's new
-
New Injection Attack Check: Added sdkPayloadIntegrityCheck for multipart SDK payloads, validating signed images and request fields and returning Reject when tampering is detected during API processing.
-
Capture resolver: When a document is successfully captured, a resolver is provided. That resolver can submit the verification request, and it can also return a v3-compliant payload for manual submission.
Previously, a result was provided on capture completion as images to be sent to the API. -
Facilitated API submission: The captured frame can be submitted immediately by the SDK when scanning finishes, or submitted later through the resolver. Requests are sent to
{base_url}/api/v3/verify. The page origin is used when no base URL is set. The receiving server forwards the body unchanged and adds the API key in theAuthorizationheader.
Note: A failed automatic submit is not retried. The same resolver can be used to resubmit while the session is still active. -
Improved capture feedback: Each processed frame reports the document side and whether the background is interfering with verification. The warning shown by the feedback UI is “Move the document to a plain background”.
-
Runtime enhancement: Browsers that support relaxed SIMD load the required WebAssembly build faster and automatically while being downloaded. The help tooltip is shown after 10 seconds.
-
Most up to date document coverage: The full list of newly supported documents can be found here, below the release notes for October 2026: https://docs.microblink.com/blinkid/release-notes
-
The capture pipeline is replaced with the v3 session, consent, and Verify API flow. Setup, capture, and submit are covered by a single component.
Note, more information on the v3 API can be found here: https://docs.microblink.com/verify/migrate-v3
1. Verification setup
Session settings accept a configuration object in the same shape as the v3 API. The configuration covers the verification policy, sensitivity thresholds, image-quality handling, extraction, and redaction.
2. Consent and Consent UI
From the roll out of the v3 API, explicit end-user consent is required for verifications prior to capture. Three options are provided, in all cases, when that dialog is declined, the SDK is terminated.
a. The built-in consent dialog can be shown.
b. The built-in consent dialog can be customised.
c. When consent has already been gathered before Verify is started, a consent object can be supplied before capture and the consent dialog is skipped.
More information on Consent Management can be found here: https://docs.microblink.com/verify/consent
Bugfixes & Improvements
- Updated additional number format checks for Western Australia driver licenses.
- Resolved false rejection issue with Philippine eIDs, now both digital and physical versions are accepted.
- Added new date formats for Irish passports and passport cards.
- Removed documentNumber logic check for AUSTRIA//DL/2006 which was causing false rejections.
- Fixed an issue where extraction processingStatus was returning incorrect values for certain multi-side documents.
- Fixed an issue where barcode ExtractionResult was returned for certain documents without barcode.
- Fixed a validation issue for dateOfIssue on Ireland rigid passports, and dateOfBirth and dateOfExpiry on Ireland residence permits.
- Fixed an issue where barcode read checks for Tennessee 2018 and North Carolina 2008 Under 21 driver licenses was previously returning NotPerformed.
- Fixed an issue where NONE would sometimes appear as part of the firstName extraction result.
- Fixed issues with document number formats for Wyoming DLs and Indonesia passports.
- Fixed issue with date formats for Brazil IDs.
- Fixed issue with barcode authenticity checks for Ontario DLs.
How the v3 flow works on Android
- Capture payload: When capture completes,
BlinkIdVerifyAnalyzer(or the capture activity) delivers aBlinkIdVerifyCaptureResult. The v3 request isserializedVerifyPayload(NativeSerializedVerifyPayload): native multipart parts (imageFirstSide,imageSecondSide,imageBarcode,configuration,consent,traceId,sdkMetadata). Submit withBlinkIdVerifyClient.verify(payload)(Kotlin) orverifyPayloadBlocking(payload)(Java).frontCameraFrame/backCameraFrame/barcodeCameraFrameremain for preview and legacy helpers only; do not re-encode them for Cloud Verify. - API submission: The SDK does not call Verify Cloud automatically. Your app creates
BlinkIdVerifyClientwithBlinkIdVerifyServiceSettingsand submits after capture. Requests go to{verificationServiceBaseUrl}/api/v3/verify(BlinkIdVerifyClient.resolveVerifyUrlaccepts bases such as…/api/v3, legacy…/api/v2, or…/api/v2/docver).tokenis required for v3; it is sent as the fullAuthorizationheader value (scheme included, e.g.Basic …or a bearer token from your backend). Optional legacy headersmb-client-sdk-name,mb-client-sdk-version, andmb-runner-versionstill exist;sdkMetadatain the payload carries SDK metadata for integrity checks. - Capture feedback: Each frame’s
BlinkIdVerifyProcessResult.resultCompleteness.scanningStatusreports scan progress (document side).inputImageAnalysisResult.screenPresenceDetecteddrives the instruction “Move the document to a plain background” (VerifyStatusMessage.MoveToPlainBackground). - Verification setup:
BlinkIdVerifySessionSettings.scanningSettingsmaps to the v3configurationJSON generated in native code:- Use case:
verificationPolicy(VerifyVerificationPolicy: HighConversion / Balanced / HighAssurance), plususeCase.verificationContextanduseCase.manualReviewStrategyonBlinkIdVerifyProcessingUseCase - Verification settings: sensitivity thresholds on
MatchLevel(screenAnalysisMatchLevel,photocopyMatchLevel,photoForgeryMatchLevel,barcodeAnomalyMatchLevel,dataMatchMatchLevel,generativeAiMatchLevel),imageQualityRetryPolicy,treatExpirationAsFraud,cropAffectsVerdict - Image assessment:
imageQualitySensitivity - Extraction / redaction:
returnFullDocumentImage,returnFaceImage,returnSignatureImage,barcodeImageReturnEnabled,redactionMode(RedactionMode, formerly anonymization) - Scanning behaviour:
scanUnsupportedBack,scanPassportDataPageOnly - Nullable fields left unset (
null) are omitted from the generated configuration; the backend default applies (same as omitting optional v3 fields).
- Use case:
- Consent: Required for BlinkID Verify Cloud. Configure via
BlinkIdVerifyActivitySettings.consentUxConfig(BlinkIdVerifyConsentUxConfig):RequireConsent— built-in consent UI before scanning;userIdrequired; optionaldurationDays,note,customerContext. Declining cancels the session (CancelReason.UserRequested).ProvideExternalConsent— skip UI when you already have a v3ExternalConsentObject(including one restored from a priorBlinkIdVerifyCaptureResult.consent).NoConsentNeeded— no consent part in the payload; self-hosted only (Cloud rejects missing consent).- Programmatic sessions: set
BlinkIdVerifySessionSettings.consentor callBlinkIdVerifyScanningSession.setConsent/BlinkIdVerifyAnalyzer.setConsentbeforegetResult().
Breaking API changes
- Package relocation (update all imports):
com.microblink.core.*→com.microblink.blinkidverify.core.*(core types are vendored into the Verify AAR; do not rely on a separatemicroblink-coredependency for Verify).- Shared UX:
com.microblink.ux.*→com.microblink.blinkidverify.ux.*; BlinkID-specific UX pieces under Verify use theblinkidverify.uxnamespace.
BlinkIdVerifyClient.verify: Primary API isverify(NativeSerializedVerifyPayload): Response<BlinkIdVerifyV3EndpointResponse>.verify(BlinkIdVerifyRequest)(JSON/docverv2) is deprecated and must not be used for Verify Cloud.- Cloud response model: Prefer
BlinkIdVerifyV3EndpointResponse(verification.verdict, nestedchecks,runtime,injectionAttackCheck/sdkPayloadIntegrityCheck). Legacy v2BlinkIdVerifyEndpointResponse/ polymorphicVerifyChecktree applies only to the deprecated client method. BlinkIdVerifyCaptureResult: AddedserializedVerifyPayloadandconsent. Per-frameEncodedImage.orientationis no longer returned from native capture (alwaysRotation0in the payload path).toBlinkIdVerifyRequest()remains for migration but builds the legacy v2 JSON request; new integrations must useserializedVerifyPayloadonly.BlinkIdVerifyScanningSettings: Extended for v3 (photocopy / portrait forgery / generative AI sensitivities, image return flags,redactionMode,imageQualitySensitivity,imageQualityRetryPolicy,cropAffectsVerdict,verificationPolicy,barcodeImageReturnEnabled,traceIdon session).staticSecurityFeaturesMatchLevelis ignored in native v3 configuration (removed in document-verification 19.4+). GranularimageQualitySettings(blur/glare/… per check) is not written into the v3 session configuration anymore; useimageQualitySensitivity(legacy request builder still readsimageQualitySettings).AnonymizationMode→RedactionModeincom.microblink.blinkidverify.core.settings.BlinkIdVerifyActivitySettings:consentUxConfigis required when launchingMbBlinkIdVerifyCapture/BlinkIdVerifyCaptureActivity.- Custom
ImageAnalyzerimplementations (incom.microblink.blinkidverify.ux.camera):restartAnalysis()issuspend;timeoutAnalysis(cause: TimeoutCause)replaces the parameterless timeout (step vs inactivity). CountryId.VirginIslandsBritishrenamed toCountryId.BritishVirginIslands(aligned with core-identity 27).
New API
BlinkIdVerifySessionSettings.traceId— optional; included in the multipart payload when non-empty; echoed inV3RuntimeInformation.traceId.VerifyUxSettings.inactivityTimeoutDuration(default 10 s;0disables) — inactivity timeout with step timeout alerts in the scanning UI.VerifyUxSettings:allowScanSound,helpTooltipShowDelay(default 10 s),helpTooltipHideDelay(default 5 s).- Consent UX:
MicroblinkConsentScreen,ConsentManager, CMS flow logging tags for integrator debugging. BlinkIdVerifyClient: HTTP 413 →ErrorReason.PayloadTooLarge, 429 →ErrorReason.RateLimitedwithResponse.Error.retryAfterSeconds, 503 →ErrorReason.ServiceUnavailable.
Behavior changes
- Default
VerifyUxSettings.stepTimeoutDurationincreased from 15 s to 60 s. - Step timer resumes elapsed time after pause (help/onboarding/lifecycle); new document side or fresh step still resets the step timer.
- Injection attack / payload integrity: Backend may reject tampered multipart payloads; inspect
verification.injectionAttackCheck.sdkPayloadIntegrityCheckonBlinkIdVerifyV3EndpointResponse. - Build tooling: Verify libraries compile with Android SDK 37; published artifacts declare
minCompileSdk36 for consuming apps.
Bugfixes & improvements
- Built-in consent screen accessibility (TalkBack, heading semantics, scrollable content).
- Client-provided SDK strings (
UiSettings.sdkStrings/VerifySdkStrings) now apply correctly in shared UX components (status messages and accessibility labels). - Screen presence user messaging during scan; scan success sounds; inactivity and step timeout pinglets.
- Passport scanning UX fixes (data-page-only flow, rotation/barcode steps).
- Document unsupported handling in the test/reference UX.
- Sample app: v3 result UI, consent CMS flow, granular Verify settings, images on the results screen.