Rightis

Developer guide

Before your AI feature uses a real person's face or voice

Building deepfake, face swap, voice clone or celebrity avatar features with a real person's face, voice or persona? Before you generate, check consent with Rightis, a likeness rights API and public registry of what each person allows under their right of publicity. Not registered is not cleared, and a holder who has said nothing is not a yes either.

Features this applies to

If a real person or character can be recognised in the output, check before you generate. These are the features people build most often.

  • Avatars and profile images

    Avatars that look like a specific person, restyled portraits, and composites that look like a photo with a celebrity.

  • Face swap

    Replacing a face in a photo or video with someone else's. The person whose face goes in is the one you check.

  • Voice clone and speech synthesis

    Reading text, singing or dubbing in a specific person's voice. Ask with voice in asset_types.

  • Celebrity chatbots and personas

    Bots that talk as a real person or character, with their name, manner and personality. It applies even without a face or a voice if the bot presents itself as that person.

  • User uploads of other people

    Nothing guarantees that the person in an uploaded photo is the uploader. Without a check that it is their own photo, treat it as someone else's face.

What checking means

  1. 01

    Decide who it is

    A check takes a Rights ID, a code that starts with BR. You can find it by searching the public registry by name. If you cannot tell who it is, you have nothing to check, and that is not permission.

  2. 02

    Describe what you will do

    Put the use in plain words in use_type, the assets you need in asset_types (face, voice, style, image), the generation method in ai_methods and country codes in territory. Set for_training separately if you will train. Generation and training are separate rights.

  3. 03

    Read the decision and the next action

    decision is one answer for the use you described, and the most restrictive scope wins. Your code follows next_action. Even when decision is allowed, the next step is to request a licence.

  4. 04

    License, then record

    Request the licence at the next_action url. An empty url means the holder is not taking requests right now. Once the licence is active, you can record use in the usage ledger and get a signed provenance manifest for each output.

Check it in code

In the SDK, rights.check calls the keyed check when an API key is set and the keyless public resolve when it is not. Both answer in the same shape. Keep the key in a server environment variable, never in browser code.

The keyless public endpoint only answers for real people listed in the public registry. The sandbox sample people are only found with a sandbox key.

Install and CLI
npm install @rightis/sdk
npx rightis check BR-XXXX-XXXX-XXXX --use "avatar generation" --asset face
SDK (TypeScript)
import { Rightis } from '@rightis/sdk';

// Reads RIGHTIS_SECRET_KEY. Without a key it calls the keyless public resolve.
const rightis = new Rightis();

const result = await rightis.rights.check({
  rights_id: 'BR-XXXX-XXXX-XXXX',
  use_type: 'avatar generation',
  asset_types: ['face'],
  ai_methods: ['image_generation'],
});

console.log(result.decision, result.next_action.type, result.next_action.url);
HTTP, no key
curl -X POST https://rightis.org/api/public/v1/rights/resolve \
  -H "Content-Type: application/json" \
  -d '{
    "rights_id": "BR-XV7E-8X7Z-ERB7",
    "use_type": "voice clone",
    "asset_types": ["voice"],
    "ai_methods": ["voice_synthesis"]
  }'
Response for a Rights ID that is not registered
{
  "rights_id": "BR-XXXX-XXXX-XXXX",
  "registered": false,
  "identity": null,
  "decision": null,
  "scopes": [],
  "unmapped": [],
  "training": { "decision": "unspecified", "do_not_train": true },
  "next_action": {
    "type": "not_registered",
    "url": null,
    "reason": "No listed registration for this rights_id. Not registered is not permission. Treat the identity as not cleared for AI use."
  },
  "profile_url": null,
  "notes": ["Rightis answers only for identities the holder chose to list."]
}

What to do with each decision

A decision is not a licence. Whatever the decision, the one thing that lets you generate is a licence that is active now.

decision: allowed
The holder pre-authorised these scopes. It is not free use. next_action is request_license, and the request can be approved without the holder reviewing it. Conditions such as the fee floor are checked when you file the request.
decision: requires_approval
The holder decides each request. Request a licence and do not generate while you wait. You also get this when words in unmapped could not be mapped to a scope.
decision: unspecified
The holder has never said anything about this use. It is not permission. Request a licence to ask them.
decision: denied
The holder refuses at least one scope this use touches. next_action is stop. Do not generate.
next_action: not_registered
The Rights ID is not in the registry, and decision is null. Not registered is not cleared. It does not mean the person has no rights, only that Rightis has nothing on record.
next_action: describe_use
The person was found but no use was described. Ask again with use_type or asset_types.

Training is answered separately. Read decision and do_not_train under training. Someone who allows generation may still not allow training.

If you could not reach Rightis or got an error, do not read it as a yes. Not being able to check is not the same as being cleared.

Turning the answer into a generate or not decision
import { Rightis, RightisError } from '@rightis/sdk';

const rightis = new Rightis(); // server side only

type Gate = { generate: boolean; reason: string; url?: string | null };

export async function mayGenerate(rightsId: string, licenseCode?: string): Promise<Gate> {
  // 1. An active licence for this use is what lets you generate.
  if (licenseCode) {
    const v = await rightis.licenses.verify({ license_public_code: licenseCode });
    // Also compare v.rights_categories, v.media_types and v.territory with your use.
    if (v.valid) return { generate: true, reason: 'active licence' };
  }

  // 2. No licence yet: ask what to do next.
  let r;
  try {
    r = await rightis.rights.check({
      rights_id: rightsId,
      use_type: 'face swap video',
      asset_types: ['face'],
      ai_methods: ['video_generation'],
    });
  } catch (e) {
    // Could not ask. Unknown is not cleared.
    return { generate: false, reason: e instanceof RightisError ? e.code : 'unreachable' };
  }

  switch (r.next_action.type) {
    case 'stop':
      return { generate: false, reason: 'denied by the rights holder' };
    case 'not_registered':
      return { generate: false, reason: 'not registered is not cleared' };
    case 'describe_use':
      return { generate: false, reason: 'describe the use and ask again' };
    case 'request_license':
      // allowed, requires_approval and unspecified all land here. None is a licence yet.
      return { generate: false, reason: r.decision ?? 'request a licence', url: r.next_action.url };
  }
}

Recording what you generated

These exist today. All three need an API key and are tied to a licence.

  • Usage ledger

    Send uses such as generation, exposure or voice synthesis against a licence code, up to 500 at a time, deduplicated by event_id. In the SDK this is usage.log.

  • Provenance manifest

    Send the SHA-256 hash of an output with the licence code and get a signed manifest back. It is not issued unless the licence is active now. The generation tool name is your declaration, not something Rightis verified. Not in the SDK yet; call the provenance path in the OpenAPI document.

  • Licence verify

    Check whether a licence is valid now, by licence code or output hash. In the SDK this is licenses.verify.

Recording usage (SDK)
await rightis.usage.log([
  {
    event_id: 'gen_01J9Z3K7',            // your id, resends are reported as duplicate
    license_public_code: 'L-XXXXXXXX',   // usage is recorded only against a licence
    occurred_at: new Date().toISOString(),
    use_type: 'generation',
    decision: 'allow',
    content_hash: outputSha256Hex,        // optional, hex SHA-256 of what you generated
  },
]);

Where the law stands

Laws in force and bills that are not law yet are listed separately. No law requires a Rightis check. A check tells you what the holder has set; it does not replace a legal assessment.

US federal

  • In force

    TAKE IT DOWN Act

    Enacted May 2025; platform duties from 19 May 2026

    Covered platforms must provide a removal request process for non-consensual intimate imagery and take the image, plus known identical copies, down within 48 hours of a valid request. AI-generated and AI-altered images are covered. The FTC has begun enforcement.

    Source: FTC
  • Bill

    NO FAKES Act

    Advanced by the Senate Judiciary Committee on 22 June 2026; not law

    A bill that would create a federal right in digital replicas of voice and likeness, with a notice-and-takedown process. If it passes, the current state-by-state patchwork consolidates.

    Source: Congress.gov

US state

  • In force

    ELVIS Act (Tennessee)

    In force since 1 July 2024

    The first US state law to protect voice as a property right, aimed squarely at AI tools that clone a person's voice without consent. Signed 21 March 2024; 2024 Tenn. Pub. Acts ch. 588.

    Source: Tennessee 주정부
  • In force

    AB 2602, AB 1836 (California)

    AB 2602 from 1 January 2025; AB 1836 from 1 January 2026

    A contract that lets someone create a digital replica of a performer's voice or likeness must state specifically what will be made and obtain consent. Digital replicas of deceased personalities require the estate's permission.

    Source: California Legislative Information

Korea

  • In force

    AI Framework Act (Korea)

    In force since 22 January 2026

    Providers of generative AI must label output as AI-generated. Deepfake output requires a label a viewer can actually see. Fines are held back during an initial grace period.

    Source: 국가법령정보센터
  • In force

    Unfair Competition Prevention Act (Korea)

    In force since 8 June 2022

    Using a well-known person's name, likeness or voice for your own business, against fair commercial practice and to their economic detriment, is an act of unfair competition. This is the practical basis for commercial likeness and voice claims in Korea.

    Source: 국가법령정보센터
  • In force

    Sexual Violence Punishment Act art. 14-2 (Korea)

    Amendment in force since 16 October 2024

    Editing or synthesising a person's face or body into sexual material and distributing it is a crime; a 2024 amendment extended punishment to knowingly possessing, buying, storing or viewing such material.

    Source: 국가법령정보센터

A summary of published statutes and government material, not legal advice. Talk to a lawyer about your own case. As of 10 September 2026.

Frequently asked questions

Is there an API to check likeness rights and the right of publicity?
Yes. Rightis has a keyless public decision API, a keyed check API, and an SDK and CLI on npm. Send a Rights ID and a described use, and it returns one of allowed, requires approval, unspecified or denied, plus a next action.
How do I check consent in a deepfake or voice clone feature?
Before you call the model, send the person's Rights ID, the use and the assets you will use (face, voice) and read the decision. Generate only under an active licence, and without one follow the next action in the answer.
If the decision is allowed, can I generate right away?
No. Allowed means a licence can be signed without the holder reviewing it, not that you may use the likeness without a licence. The next action is still a licence request.
Can I use someone who is not registered with Rightis?
No. Likeness rights and the right of publicity exist without registration. Not registered means Rightis has no record, not that you have permission. Treat a failed check the same way.
Likeness rights API: check consent before your AI uses a real person's face or voice | Rightis