Integration overview
Face Matcher exposes everything it produces through four surfaces: a REST API for commands and configuration, a GraphQL API for queries and real-time subscriptions, a RabbitMQ broker for message-based notifications, and an S3 store for images. Station, the bundled web UI, is itself a client of these surfaces, so anything Station can do, your own application can do as well. This section documents each surface from an integrator's point of view; how the recognition pipeline works is covered in the Face Matcher Server manual.
The four surfaces
| Surface | From the host | Inside face-matcher-network | Typical use |
|---|---|---|---|
| REST API | http://localhost:8098 (Swagger UI at the root) | http://api:8080 | Manage watchlists, enroll members, identify and verify faces, configure cameras and edge streams |
| GraphQL API | http://localhost:8097/graphql | http://graphql-api:8080/graphql | Query stored faces, tracklets and match results; subscribe to live events |
| RabbitMQ | localhost:5672 (AMQP), 1883 (MQTT), 5552 (streams), management UI on 15672 | rmq:5672, rmq:1883, rmq:5552 | Consume notifications from a message queue; receive edge-device frame data |
| S3 storage | http://localhost:8333 | http://seaweedfs:8333 | Read face crops, full frames and enrollment images by their image data ID |
Station talks to the same endpoints: it reads CORE_API_ROOT=http://api:8080/api/v1 and GRAPHQL_ROOT=http://graphql-api:8080/graphql from .env.station, and it serves images to the browser through pre-signed S3 URLs. Authentication is off by default on all surfaces; the Authentication guide explains how to put the REST and GraphQL APIs behind OAuth2/OIDC.
Building a stack on top of Face Matcher
A product built on Face Matcher joins its Docker network and depends only on the items in the table below. Everything else in the deployment is internal and may change between releases. The Smart Corridor solution is built exactly this way: it vendors an unmodified copy of Face Matcher and relies on this integration list alone.
| Item | Value |
|---|---|
| Network | face-matcher-network, created by run.sh. Join it with external: true in your own Compose file. |
| REST API | api:8080 |
| GraphQL API | graphql-api:8080. Face templates are included in notifications (Notifications__IncludeTemplates=true). |
| RabbitMQ | rmq:5672 AMQP, rmq:1883 MQTT, rmq:5552 streams |
| S3 | seaweedfs:8333. Use your own bucket; face-matcher belongs to the platform. |
| PostgreSQL | pgsql:5432 |
| Station | fm-station:8000 |
| Admin image | ${REGISTRY}admin:${VERSION} from .env (database migrations and CLI tasks) |
| Credentials | All in .env (RabbitMQ section 2.2, S3 section 2.4, database section 2.1). The shipped values are development defaults; change them before production. |
| License | One iengine.lic in secrets/, see Get a license. Your stack does not need its own copy unless it runs a biometric engine itself. |
| Start order | Face Matcher first. start.sh reads STATION_IDENTIFICATION and STATION_PUBLIC_HOST from the environment. |
A minimal Compose fragment for a service that joins the network:
services:
my-service:
image: example/my-service:1.0
environment:
- FACE_MATCHER_REST=http://api:8080
- FACE_MATCHER_GRAPHQL=http://graphql-api:8080/graphql
- RABBITMQ_HOST=rmq
networks:
default:
name: face-matcher-network
external: true
Pages in this section
- REST API and the Enroll and identify via REST walkthrough.
- GraphQL API and GraphQL samples.
- RabbitMQ notifications and S3 storage.
- Enhanced preview for annotated video in third-party players and VMS.
- Auto-enrollment add-on.
- Compatibility matrix.
Face Matcher is delivered as a fixed-scope product: the APIs above are the extension points, and there is no custom feature work or one-off extension of the platform itself.