Latest from the Didit blog.
Verified API Access for AI Model Providers: A Risk-Tiered Architecture
How to bind high-risk model access to verified people and businesses without taxing every developer who signs up — access tiers, trigger conditions, the endpoints for each tier, and what each one costs.
Face Search 1:N: Finding Every Account One Person Controls
One API call searches a face across every verified user you have and returns each matching account with your own identifier attached. Free with Didit verification — the primitive that turns an account list into an actor map.
Biometric Step-Up for AI API Access: Binding Privilege to a Person
Onboarding proves who signed up. It proves nothing about who is holding the API key six months later. Passwordless biometric re-authentication for quota increases, credit grants and key issuance — $0.10, sub-two-second.

Hydra Account Networks: How 20,000 Accounts Become One Actor
Cut off one account and two more appear. Hydra networks beat per-account review by design. Here is how cross-account linking — face, device, IP, email, phone — collapses thousands of accounts into a single resolvable actor.

Blocklist Propagation: Making One Confirmed Abuse Case Kill the Whole Network
Banning an account removes one head from the hydra. Blocklisting from a session auto-extracts every identifier it touched — face, document, phone, email, IP, device — across 12 entry types, so the next account fails at the door.
Detecting Account Farming on AI APIs With Device and Network Signals
Farmed accounts are cheap at the account layer and expensive at the physical layer. The device and network warning codes that expose emulators, automation, tampered clients and recovered devices — $0.03 per check.