Handles `POST /v1/verify/face-match`.
Errors
Returns 400 for undecodable image payloads, 422 when an image cannot
be evaluated, and 503 when evidence or verification storage is
unavailable. A repeated Idempotency-Key returns 200 with the original
verification rather than matching the faces again; see [crate::idempotency].
Authorizations
A tenant API key. Acts for exactly one tenant and cannot conclude a case, because a conclusion records a person.
Body
Face-match verification request body.
There is deliberately no tenant_id field. It used to be here, and the
handler trusted it: any caller could name any tenant, and the route
required no credentials at all, so biometrics could be submitted and
evidence written against somebody else's account. The tenant now comes from
the presented credentials like every other /v1 route, which is the only
place it can come from and still mean anything.
Response
A replayed Idempotency-Key; the original verification
Face-match verification response body.
Decision outcome.
ALLOW, WARN, BLOCK, HOLD, REVIEW_REQUIRED, FLAG, BLOCK_RECOMMENDED, SUSPEND, END_STREAM Decision record identifier.
References to retained evidence.
Explanation reasons.
Review lifecycle state.
PENDING, APPROVED, OVERTURNED, NOT_REQUIRED Explainable risk level.
LOW, MEDIUM, HIGH, CRITICAL Verification attempt identifier.
Manual-review case, when the decision is borderline.

