OpenID Connect KYC handoff
Send people to MIMI for KYC.
Your application starts a standard OIDC authorization request. MIMI takes the payment, runs the identity checks your client requires, issues the certificate, then returns an authorization code to the callback URL you registered.
Request an integrationWhat works now
Payment, ID or passport, live face, three questions, passkey, signature and the digital certificate. MIMI re-checks every one against the system that owns it before returning a code, so the code is the proof.
What your application receives
Your backend receives the normal OpenID Connect account details after MIMI enrolment. MIMI does not send document images, biometric data, or other raw KYC material.
The customer journey
- 1. Sign in. Google through SecurySign. Silent if you signed the customer in already.
- 2. Pay. Your price, by M-Pesa or card, for a 365-day subscription on their account.
- 3. ID or passport. The customer captures the document and it is checked against the register.
- 4. Live face. Liveness, matched against the document portrait.
- 5. Three questions. Asked one at a time, answers stored as hashes.
- 6. Passkey and signature. One tap sets up the passkey and captures the drawn signature.
- 7. Certificate. Issued automatically, then MIMI returns the customer to your callback.
The handoff
Use Authorization Code flow with PKCE.
Read discovery, generate a new `state`, `nonce`, and S256 PKCE challenge for every attempt, then redirect the browser to the authorization endpoint. MIMI requires PKCE for every client. If you signed the customer in already, name them with `claims` so MIMI onboards that account rather than whoever else is signed in on the browser.
GET https://staging.mimi.ke/authorize?
client_id=your-client-id&
redirect_uri=https%3A%2F%2Fapp.example.co.ke%2Fauth%2Fmimi%2Fcallback&
response_type=code&
scope=openid%20email%20profile&
state=<random-state>&
nonce=<random-nonce>&
code_challenge=<S256-challenge>&
code_challenge_method=S256&
claims={"id_token":{"sub":{"value":"<their sub>"}}}Discovery: https://staging.mimi.ke/.well-known/openid-configuration
What happens after the redirect
- 1. Check `state`. Reject a missing or mismatched value.
- 2. Exchange the code. Send the one-time code, redirect URI, and original verifier to the token endpoint from discovery.
- 3. Verify the ID token. Check its issuer, audience, expiry, signature, and the nonce you stored.
- 4. Create your account. Use the returned `sub`, `email`, and `name` as ordinary OIDC identity claims.
To land the customer on a particular page of yours, carry it in `state` and redirect from your callback. MIMI only returns people to a callback URL you registered, so it will not take a destination as a request parameter.