https://help.openai.com/en/articles/10910291-api-organizatio...
https://help.openai.com/en/articles/10910291-api-organizatio...
I’m not talking about sketchy prepaid cards from weird banks on a VPN in a country the United States doesn’t do business with. I’m talking about Americans getting their Chase cards rejected on their home wifi in Ithaca.
When this initially happened to me, I assumed it was a one off thing, but I was shocked to have found out that it’s been going on for at least six months, probably longer.
Wasn't AI supposed to solve this? /s
Turns out it wasn't dogfood.
This didn't use to be the case (OpenRouter's OpenAI access used to be bring-your-own-key), but they've reached some sort of deal with them a couple months ago, and now you can access all the GPT-5 series models on OR with no verification at all.
> At this time, retries are not supported. You can continue using OpenAI’s platform with your existing access.
That's ridiculous, especially as their list of reasons that verifications can fail include "There was a technical issue during submission".
I then looked at their age verification and it used that problematic company so I cancelled out.
Why on earth not?
This is incorrect, the Digital Credentials API[1] is designed so that identity information can be remotely verified in a cryptographically secure manner.
There is no reason Anthropic could not use the DC API for this in countries and states that support digital identity, I assume they simply aren't because they threw this together at the last minute and simply out-sourced it to Persona.
They could have vibe-coded their own verification system that uses DC APIs. It shouldn't take long, assuming that Anthropic still has access to Fable. /s
Why would they care about _you_ when they have just a bit short of a billion users and they are up for a huge IPO? Of course they won't even bother implementing a retry.
I dealt with a few instances of online ID verification recently, and in my experience, they don't close your application when your photo is not clear. They mark it as "awaiting customer response" and kindly ask you to upload again.
Indeed, that's what motivated me to get an OpenRouter account!
what did you do to trigger a verification process?
To me, without documented use cases where you might/likely/certainly trigger identity verification, how can I properly limit my curiosity as someone who will gladly stay on the safe side for SOTA cloud model use? I'll happily stay away from these topics if I'm informed on what they are, even if the docs are vague.
Does anyone have insight into the answer to this? What API calls? What user behavior? What topics should I let go unanswered (or converse about with local LLMs) if I want to avoid losing access to the tooling?
The thought that they don't/won't publish this document should scare everyone. That leads to "because I said so" service refusal that is a very slippery slope.
I do understand that all businesses are allowed to refuse service to me in the USA, from food trucks to AWS, and that's fine with me. But at least tell me your rules and extra verification trigger criteria so I have a chance of not using your service in a way that concerns you.
That is not in any way related to Fable (visibly) being switched to a less strong model if you’re trying to discuss certain topics.
i disagree, but it seems clear, from how you put it, that there's no point explaining the why
We're talking about it being invisibly moved to a weaker model if it looks like you're distilling (which is best detected through something that is at least partially a reputational / account metric).
Now, Anthropic stepped away from this, but it highlights one more kind of systemic risk you're exposed to when you're not running the model yourself.
1. Anthropic certainly has the ability.
2. They’re willing to use it silently.
Thankfully I don't depend on any of such services. It would make me rather angry.
If you're willing to wait a couple years, I dare say a few services might have changed their minds by then, so it's too early to judge.
In Reddit's case it means you can continue to post and comment, it's just that your posts and comments are no longer seen by others.
For a paid product, it's really not that hard to already have a fairly solid idea of what's going on - this just ensures that a responsible adult has gone through a clear process of signing off on the identity for this specific service, rather than a kid with their parent's credit card.
I see you have an uncommon name.
My first+last are shared by about 20,000 people in the US. From 2005-2020 I was unable to check-in for airlines online or even at the kiosk at the airport. I had to wait on line for baggage check-in despite never checking a bag, and they'd take my ID into the back room and delay me for 15 minutes and whisper and glare at me the whole time. Thankfully I can finally fly like a normal person again.
When I worked at a large company, there were four other people with the same first name, middle initial, and last name.
There is nothing surprising or rare about two customers having the same name.
But the sequel: a few years later I get a bill from a hospital for copay for delivery/childbirth. I call to contest ... we did not even live there any more, did at some point of time but years apart ... but they are adamant that my wife gave birth, at that hospital, on that date, in that city, and maybe she never informed me :) it was almost that weird. I don't act on it and give them a statement that it is not me/my family. Then another bill (or a final notice) a couple of years later. And then finally something clicks ... I used to work in a team where when I moved out, someone replaced me and his name was also same as me. Reach out to him, and his wife's name is same as mine, and they lived in the same city we lived in.
So someone somewhere fat fingered the wrong account when searching by name. He acknowledged the account (and childbirth) and paid up. I unfortunately did not ask him about his wife's date of birth to solve the immigration mystery.
My suspicion has been at my past employer's HR or legal department mixing up files
They know who you claim to be. It’s not like they just delete all information about you when you fail verification. They are perfectly capable of seeing that two separate accounts are both claiming to be the same person.
> Otherwise what stops me DoSing Sam Altman's account by saying I'm him and then failing to verify?
For Sam Altman in particular? The fact that he’s the CEO. For people in general? Do you have their passport / driving license, and other details needed to attempt the verification process?
E.G> when Taylor Swift wants to call Apple right now, how would she know what number to call?
Incidentally, https://people.com/pope-leo-was-hung-up-on-by-bank-customer-...
Pope Leo is not that rich, and had lived outside the US for many years (he came up in the church hierarchy of Latin America), so it’s not that surprising that he ran into this situation.
It goes something like this (it varies by country / citizenship): first you upload a picture of your ID, then you use your phone to take a video of your face, then the two are matched. A failure is when the uploaded ID doesn’t match your face.
You can’t get to the part where they don’t match without uploading a picture of their ID. If you don’t have their ID, then you can’t fail to match. If you fake the ID, then when they come to upload their own ID, their ID won’t match your fake ID and they won’t be blocked.
You do not need real documents if your goal is to get the person locked out by using fake documents.