Knowledge-Based Authentication: Verify Signers Before They Sign
Verify U.S. signers in seconds with security questions drawn from public records, so there's no ID to upload and nothing a fraudster can guess. Built for loans, closings, and contracts where a disputed signature is expensive.
- 30-day free trial
- No credit card required
- Web app and API

Identity verification without the ID upload
Knowledge-Based Authentication (KBA) confirms a signer's identity with questions only they can answer. Generated fresh from public records on access, so there's nothing to research beforehand and nothing static to guess.
What the signer provides
Their name, address, and the last four digits of their SSN. These details are used only to generate the security questions and aren't stored anywhere.
What the signer does
Answers the security questions right where they're signing. No account to create, no app to download, no camera needed, typically done in under a minute.
Why KBA matters
Most agreements don't need identity proofing. A few carry consequences you can't undo, and on those, knowing that someone opened the link isn't the same as knowing who signed.
Where identity is required, not optional
IRS Form 8879 e-filings, real estate closings, loan payoffs, and beneficiary changes on estates all require the signer to be who they claim, or the paperwork itself is at risk.
Verifies the person, not the inbox
Email and SMS codes only prove someone has access to an inbox or phone. KBA verifies identity through public-record questions tied to the real person.
Harder to defeat than static questions
Security questions are generated fresh from the signer's credit and public record history at the moment of signing, so there's nothing for a fraudster to look up in advance.
Keeps high-value deals moving
KBA verifies signer identities in seconds using public records. No documents to upload and no manual reviews that can slow down your deals.
KBA or ID Verification?
Compare KBA and ID Verification to find the right fit for your signers and use case.
Knowledge-Based Authentication | ID Verification | |
|---|---|---|
What the signer does | Answers security questions | Uploads a government ID |
What’s checked | Identity details from public records | Document authenticity and photo match |
Setup for signer | None, just answer | Camera or scanned upload |
Speed | Instant, no document to process | Slower, depends on image quality |
Availability | U.S.-based recipients only | Available more broadly |
Billing | Tracked and billed separately | Tracked and billed separately |
Use KBA when your signers are U.S.-based and speed matters. Use ID Verification for international signers or when you need a face-to-document match.
Three steps, no new setup
Enable it per signer, and BoldSign confirms who's signing without touching your existing send flow or requiring a separate setup.
Enable KBA for the signer
Enter their legal name and email, then turn on Knowledge-Based Authentication in their authentication settings.

The signer confirms their identity details
BoldSign uses them to generate personalized security questions.

Correct answers unlock the document
Failed attempts are capped by your retry limit, so unauthorized users are locked out.

Test the full KBA flow before you're billed for a single attempt
Sandbox mode runs the complete verification flow against a predefined test identity, so you can validate your integration end to end at no cost.
- Set authenticationType to KBA on any signer
- Configure frequency, retry count, and name matcher in the request
- Same behavior across REST, .NET, Java, Node.js, Python, and PHP SDKs
curl -X POST 'https://api.boldsign.com/v1/document/send' \
-H 'X-API-KEY: {your sandbox API key}' \
-F 'Files=@agreement.pdf;type=application/pdf' \
-F 'Title=Agreement' \
-F 'Signers={
"name": "John Smith",
"emailAddress": "signer@example.com",
"authenticationType": "KBA",
"kbaSettings": {
"type": "EveryAccess",
"maximumRetryCount": 3,
"nameMatcher": "Strict"
}
}'
# Sandbox requests use the predefined John Smith
# identity and never incur a live KBA charge.
Set defaults, override when needed
Set your account-wide defaults once in admin controls, then adjust them for an individual signer whenever a specific agreement calls for tighter or looser rules.
Verification frequency
Decide how often a signer re-verifies: every access, every access until signed, or once per document. Tighten it for agreements that stay open for weeks.
Retry attempts
Allow one, two, or three tries before the document locks. Enough to block repeat guessing, enough to forgive a genuine typo from a real signer.
Name-match tolerance
Choose none, lenient, moderate, or strict. Loosen it so a middle initial doesn't block a legitimate signer, or tighten it when the name has to match exactly.
Lockout recovery
If a signer gets locked out, reset KBA for them yourself. The document stays live and the deal keeps moving, with no restarting and no resending needed.
Add Knowledge-Based Authentication
to your next high-value agreement
- KBA included in the trial
- No credit card required
Frequently asked questions
No. KBA verifies identity through security questions only.
U.S.-based recipients only. For international signers, use ID Verification.
Usually a mismatch between the legal name on the document and their identity records, incomplete details, incorrect answers, or an expired session.
They're blocked until the sender resets KBA or removes the authentication. The document itself is unaffected.
Yes, to any signer on an existing document.
No. The last four digits are used only to generate questions and are not retained anywhere.
Sign up for your free trial today!
- 30-day free trial
- No credit card required
- 30-day free trial
- No credit card required