use case / signup risk and KYC
Username verification for KYC
Username verification for KYC checks the handle a new user gives you against 300+ public sites. Through the API you see how many public profiles use that name, whether they link to each other, and whether the handle imitates a known brand, as one more signal before you approve an account.
What a handle tells you at signup
Fraud teams already look at the email domain, the device and the payment method. The username is often ignored, even though the user chose it and it is cheap to check. A handle that has existed for years on several public platforms, with the same display name and links between profiles, describes a different kind of account than a random string that appears nowhere.
Neither result is a verdict on its own. Plenty of honest people use a fresh handle for every service, and a long public history can belong to anyone who picked the same name. What changes is the context: a thin footprint plus a risky payment pattern, or a handle that copies a well known brand, deserves a second look.
How many sites have a public profile at that address.
A deterministic 0 to 100 score that the found profiles belong to the same person, from display names, avatar hashes and cross links.
Readable reasons behind the score, so an analyst can explain a decision.
When your workspace first saw each profile, useful when the same handle signs up again.
Reading the result in a risk model
Teams usually map lookup results to a few bands and combine them with their own signals. These are starting points to adapt, not rules we enforce.
| Result | What it may mean | Common handling |
|---|---|---|
| Several found profiles, high confidence | An established public identity under this handle | Neutral or positive signal, normal flow |
| Several found profiles, low confidence | A common name used by different people | Neutral, rely on other signals |
| No found profiles | A new or single-purpose handle | Neutral alone, weigh with payment and device risk |
| Handle copies a known brand with a suffix | Possible impersonation account | Manual review before the account can message others |
| not_searchable | The owner opted out of results | Neutral, never treated as risk |
One call in your signup flow
Call the username endpoint after the user submits the form, store the lookup id with the account, and let your rules engine read found_count and confidence. If the lookup is still running, poll the id in a background job. Polling is free.
Full fields and error codes are in the username lookup API reference.
curl "https://usernamelookup.com/api/v1/username/new_user_42?wait=10" \
-H "Authorization: Bearer ul_live_your_key"
{
"id": "lk_4n7x1p0a",
"username": "new_user_42",
"status": "running",
"found_count": 1,
"confidence": null,
"poll_url": "https://usernamelookup.com/api/v1/lookups/lk_4n7x1p0a"
}
Example values with the sites list left out.
After signup, during reviews
The same lookup helps when a report comes in. An analyst opens the account, runs a lookup of its handle in the dashboard and sees the public profiles, the history of earlier runs and the differences between them. On the Investigator plan and above, case notes, evidence snapshots and a PDF report keep the review documented.
When the report is about someone impersonating a brand or a creator on your platform, fake account detection lists lookalike handles of the real account across other sites too, which helps judge whether it is an isolated copy or part of a campaign.
Paste up to 100 handles from a ring of linked accounts and compare them in one view.
See which profiles appeared or disappeared since the last run of the same handle.
URL, timestamp, HTTP status and page title captured for each profile you keep.
Responsible use in a risk process
We check public profile addresses only. The service does not return names, contact details or anything from behind a login, and it does not try to link a handle to a real person. Results should never be the only reason to refuse someone, and your users should be able to ask for a human review.
Anyone can remove their username through the opt-out page. For other teams that use lookups, see username lookup use cases.
Questions about username verification for KYC
Is username verification a replacement for identity verification?
No. It is an extra signal next to document and payment checks. It tells you whether the handle a user picked has a public footprint elsewhere and whether it copies a known brand. It does not prove who a person is, and we never try to identify the person behind a handle.
How fast is a check at signup?
Most sites answer within a few seconds. The API waits up to 25 seconds and returns what is ready. If you need an instant decision, request a subset of categories and poll the lookup id later for the full result without using extra quota.
What happens when a user has opted out?
The API returns status not_searchable for that username. Treat it as neutral, not as a risk signal. People have a right to remove their handle from our results.
Which plan fits a trust and safety team?
Investigator gives 10,000 API calls a month with the confidence score, bulk lookups and evidence snapshots. Teams screening higher signup volume use Brand Monitoring with 50,000 calls or Brand Enterprise with 500,000 calls, single sign-on and an audit log.
Check a handle the way the API sees it
Run one lookup across 300+ sites and look at the same fields your rules would read.