Skip to main content

Age Verification

Admin

Age verification adds an age gate to the POS register that requires staff to confirm a customer's age before proceeding with age-restricted products. This is essential for compliance in cannabis, alcohol, and tobacco retail.

Feature flag required

Age verification is only available when Enable Age Verification is enabled in your store settings. Navigate to Settings > Edit Settings > Tax & Currency tab and toggle on Enable Age Verification. (The Age Verification section sits below the tax settings on the same tab.)


How Age Verification Works

When enabled, the POS displays an age verification prompt when a customer attempts to purchase age-restricted products. The cashier must confirm that the customer meets the minimum age requirement before the sale can proceed.

The prompt is a simple confirmation -- the cashier visually checks the customer's ID and taps Confirm to proceed.


Configuration

Accessing Age Verification Settings

  1. Log in to the Admin Panel.
  2. Navigate to Settings > Edit Settings.
  3. Click the Tax & Currency tab.
  4. Scroll down to the Age Verification section (located below the Additional Tax settings).

Settings

SettingDefaultDescription
Enable Age VerificationOffMaster toggle to enable or disable the age gate.
Minimum Age19The minimum age required to purchase age-restricted products (valid range 1–99). Set this to match your jurisdiction's legal requirement.
Verification ModeWhen adding to cartWhen the age verification prompt appears (see below).

Verification Modes

ModeWhen the Prompt Appears
When adding to cartThe prompt appears when an age-restricted product is first added to the cart. Once the cashier confirms age for a cart, the prompt does not re-appear for additional age-restricted items in the same cart.
At checkoutThe prompt appears at checkout before payment is processed. All items are in the cart, and age is verified once before the sale completes.
Which mode to choose?

When adding to cart is recommended for most stores. It catches age issues immediately and prevents building a cart that cannot be sold. At checkout mode is useful if you want to allow browsing and only verify at the point of sale.

Marking Products as Age-Restricted

Age verification only triggers for products flagged as age-restricted. The flag is set at the category level: any product whose category (or parent category) has "Age Restricted" enabled will trigger the age prompt. Configure this from Categories in the admin panel.


POS Age Gate Behavior

When the age verification prompt triggers on the POS:

  1. An Age Verification Required modal appears asking the cashier to verify the customer's age.
  2. The modal message includes the minimum age required (e.g., "Customer must be at least 19 years old to purchase this item. Has the customer's age been verified?").
  3. The cashier checks the customer's ID.
  4. The cashier taps Age Verified to confirm the customer meets the age requirement.
  5. The sale proceeds normally.

If the cashier determines the customer does not meet the age requirement:

  1. Tap Cancel to close the modal.
  2. The age-restricted product is not added to the cart (When adding to cart mode) or the payment is blocked (At checkout mode).
ID every time

Train staff to ask for ID on every age-restricted sale, regardless of how old the customer appears. Compliance regulations typically require verification on every transaction, not just when the customer looks young.


Cannabis Compliance Context

For cannabis retail stores, age verification is a critical compliance requirement:

  • Legal requirement -- Most Canadian provinces require customers to be 19+ to purchase cannabis (18+ in Alberta and Quebec).
  • Set the correct minimum age for your province.
  • Combine with purchase limits -- Age verification works alongside the daily purchase limit tracking to ensure full compliance.
Age verification is not persisted on the sale record

The age verification confirmation is a cashier-side gate only -- there is no stored "age verified" field on completed sales. If your compliance regime requires proof-of-ID records, keep a physical log or use a dedicated ID-capture solution. Brother POS's built-in age gate is a point-of-sale prompt, not an audit record.


Online & Delivery ID Verification (Didit)

The cashier age gate above covers in-person sales at the register. For online, delivery, and wholesale orders -- where no staff member sees the customer face to face -- Brother POS offers a separate, automated identity check powered by Didit (a third-party ID-verification service). The customer photographs their government ID (and, on the stronger tier, takes a selfie), Didit confirms it is real and matches, and the order is cleared for dispatch.

Separate from the register age gate

This is a different feature from the POS Age Verification toggle. The register gate is a cashier confirmation; Didit verification is an automated document/selfie check for orders placed without a clerk present. A store can use either, both, or neither.

Each store connects its own Didit account and gets 500 free verifications per month. Configure it under Settings > Edit Settings in the Delivery ID Verification section.

Turning It On

SettingWhat it does
Enable ID Verification for DeliveriesMaster toggle. When on, local-delivery (and pickup) orders require an identity check before the order becomes dispatchable.
Verification levelHow thorough the check is -- see the table below.
Ask for last 4 of card at checkoutOptional convenience for drivers: the customer enters the last 4 digits of the card they'll present at the door, so the driver can match it on handover. This is not identity verification, and last-4 alone is PCI-safe (not protected card data).

You also enter your Didit API key, webhook secret, and the two workflow IDs (one for each level) from your Didit account. Point your Didit webhook at your-store.brotherpos.ca/webhooks/didit.

Verification Levels

LevelWhat the customer doesUse when
OffNothing -- verification disabled.You don't need automated ID checks.
ID onlyPhotographs their government ID. Didit confirms it's a real, valid document.You want a light-touch check with minimal friction.
FullPhotographs their ID and takes a selfie. Didit confirms the ID is real, the face matches, and checks liveness and IP.Recommended for delivery -- it proves the person, not just the document.
Both levels are free

Both tiers count against the same 500/month free quota, so choose by how much friction you want your customers to go through -- not by cost. Full is recommended for delivery.

The Verify-First Flow

Verification is designed so a slow or unreachable ID service can never strand a paid order. Brother POS does not call Didit while the order is being placed. Instead:

  1. The customer places and pays for their order normally.
  2. The order is stamped "ID verification pending" and cannot be dispatched yet.
  3. The order confirmation page shows a prominent Verify my identity button.
  4. When the customer taps it, Brother POS creates the Didit session on demand and sends the customer to Didit's hosted photo flow.
  5. Didit confirms the result and notifies Brother POS. The order clears for dispatch automatically.
What happens if Didit is down?

The check fails open -- a paid order still goes through and staff see a flag on it, so a third-party outage can never trap a customer's money or block an order indefinitely.

Verify Once Per Account

A customer who has an online account (storefront or WooCommerce) only has to verify once. After they pass, their account is stamped as verified, and every future order inherits that approval with no re-check -- as long as the earlier check met or exceeded the level the new order requires (a Full pass also satisfies an ID only requirement, but not the other way around).

Guest / walk-in orders keyed only to a typed-in email cannot skip verification -- account memory is trusted only for genuine account holders.

Wholesale Checkout Gate

For the wholesale portal, verification is a one-time check the buyer completes before they can place any order. On the checkout page the buyer sees an inline amber notice -- "Verify your identity to place this order" -- and the Place order button stays disabled until they pass. The page never redirects them away; they verify in place and the button unlocks (Brother POS also confirms the result the moment they return, so they don't have to wait for the background notification). A server-side backstop rejects any unverified order even if the disabled button is bypassed.

The Staff Panel

On the admin order detail page (storefront and wholesale orders), an Identity verification panel shows staff the result. Access is limited to admin, manager, and store-owner roles.

What staff seesMeaning
Green ID Verified pill (with level, e.g. "ID Verified · Full")The customer passed, and when.
Gray Not verified pillNo successful check on file.
Card at door: •••• 1234The last-4 the customer entered, if that option is on -- a handover convenience for drivers.
View selfie buttonLoads the customer's selfie and ID photo live from Didit at click time.
Selfie and ID photos are never stored

The View selfie button pulls the images straight from Didit using short-lived links generated at the moment you click -- the photos never touch Brother POS's database or disk. They're loaded on demand for a quick door-match check and are not retained. Order lists also show a compact badge ("ID verified" / "ID pending" / "ID in review" / "ID declined").

How the Result Comes Back Securely

When Didit finishes a check it notifies Brother POS over a secure webhook. Brother POS cryptographically verifies that each notification genuinely came from Didit (using your store's webhook secret) before trusting it, rejects anything outside a short time window, and ignores duplicate retries. You don't have to do anything -- this happens automatically.


Best Practices

  • Set the correct minimum age for your jurisdiction. Do not assume 19 -- check your local regulations.
  • Use "When adding to cart" mode for immediate feedback. This prevents building large orders that cannot be completed.
  • Train all staff on proper ID verification procedures. The POS prompt is a reminder, not a substitute for proper training.
  • Post signage at the entrance about age requirements to set expectations before customers reach the register.
  • Use Full verification for delivery. For orders leaving your premises, the selfie + face match on the Full tier proves the person receiving the order is the one who ordered it.

What's Next?