KYCVerify for India
Indian identity, verified on Indian terms.
Aadhaar's offline formats are signed by UIDAI. KYCVerify verifies those signatures, validates PAN, reads Indian cards and keeps the minimum, encrypted and purged on your schedule.
- Aadhaar offline formats, signature verified
- 2
- Indian cards read by OCR
- 4
- Aadhaar digits kept from offline artefacts
- Last 4
- default retention, 1 to 3,650 per app
- 90 days
Indian identity
Every Indian document a KYC flow meets.
Aadhaar Secure QR
Scan the QR on an Aadhaar letter or e-Aadhaar. The number is decoded, decompressed and its RSA signature verified against UIDAI's certificate.
Offline e-KYC XML
Upload the ZIP from UIDAI with its share code. The XML-DSig signature is verified and files older than your limit refused.
PAN
Format, holder type and name initial validated; card photo read back by OCR and compared. Structural only, stated plainly.
Indian cards by OCR
Aadhaar, PAN, voter ID (EPIC) and Indian driving licences, read from the bilingual card. A field that cannot be found stays empty.
Face match to the signed photo
With no document portrait, the selfie is matched against the photo inside the UIDAI-signed artefact.
Passports too
Indian passports and every other ICAO 9303 document through the MRZ, check digits recomputed.
Aadhaar Secure QR
Scan the letter. Check UIDAI's signature.
The QR on every Aadhaar letter and e-Aadhaar carries the resident's details and a 2048-bit RSA signature from UIDAI. KYCVerify verifies it against UIDAI's own certificates, including older keys that still sign older letters.
- Decoded in the browser from the camera, or on the server from a photo.
- Version 2 and later codes, with the last-four-mobile field, are understood.
- Reports which certificate verified the signature.
QR text
one very large base-10 integer
Big-endian bytes
a GZIP stream (zlib accepted)
Decompress and split
fields delimited by 0xFF, then photo and hashes
RSA-2048 verify
SHA256withRSA over every byte before the last 256
Record
last 4 digits, demographics, photo
- indicator0-3
- reference idlast 4 + timestamp
- name · dob · genderdemographics
- address11 fields
- photoJPEG 2000
- hashesemail, mobile
- signature256 bytes
Offline e-KYC XML
The ZIP from UIDAI, verified to the byte.
Residents download a share-phrase-protected ZIP from UIDAI. KYCVerify opens it, checks the XML-DSig digest and signature, and refuses files older than your limit (3 days by default).
If the XML was edited after UIDAI signed it, the check says exactly that: the document digest does not match.
ZIP + share phrase
ZipCrypto or AES; wrong phrase is reported
OfflinePaperlessKyc
reference id, Poi, Poa, Pht, Signature
Digest check
enveloped-signature transform, C14N, compare DigestValue
Signature check
RSA PKCS#1 v1.5 over SignedInfo, UIDAI certificates only
Age check
generated within max_xml_age_days (3)
The certificate inside the XML's KeyInfo is ignored: trust comes only from the UIDAI certificates you install in certs/uidai.
Minimum by design
What an Aadhaar check keeps.
The offline formats never carry the full number. Card photos do, so decide with counsel whether to accept them and how they fit your Aadhaar Data Vault obligations.
| Data | Stored | How |
|---|---|---|
| Aadhaar number | Last four digits | Neither offline format contains the full number. If a workflow accepts a photographed Aadhaar card, the number is read to validate it and kept masked with a keyed fingerprint; the encrypted card image, which shows it, is purged with the session. |
| Name, birth date, gender, address | Yes, with the session | From the UIDAI-signed record. Purged with the session. |
| Photo | Encrypted file | JPEG 2000 (Secure QR) or JPEG (XML), AES-256-GCM at rest; used for face match. |
| Mobile and email | Never in clear | Only UIDAI's hashes, used to confirm an email the person typed. |
| Offline XML ZIP | Encrypted file | Kept as evidence for reviewers until the retention period ends. |
| Share phrase | Not kept | Used once to unlock the ZIP. |
PAN
Structure, holder type, name initial.
Ten characters carry more than they seem. KYCVerify checks the format, decodes the holder type and compares the fifth character with the surname. With a card photo, it reads the PAN back and compares.
Structural only. Confirming that a PAN exists and belongs to this person needs a lookup through a licensed provider, which KYCVerify does not make. Every PAN result says government_lookup: false.
- ABCSeriesthree letters, AAA to ZZZ
- PHolder typeP individual, C company, H HUF, F firm, A AOP, T trust, B BOI, L local authority, J artificial juridical, G government
- EName initialsurname for individuals, entity name otherwise
- 1234Sequencefour digits
- FCheck lettera letter; the algorithm is not published
Indian cards by OCR
Read from the card, nothing invented.
Bilingual cards are read from their English side, with Hindi gender words understood. A field that cannot be found stays empty and is listed as an issue.
Aadhaar card / e-Aadhaar print
Reads
Name, date or year of birth, gender, address from the back
Number masked to XXXX XXXX 1234; a 16-digit VID is never mistaken for it.
PAN card
Reads
PAN, name, father's name, date of birth
Both the labelled layout (since 2018) and the older unlabelled one. OCR letter and digit confusions in the PAN are repaired.
Driving licence
Reads
Licence number, name, relative's name, date of birth, validity, address
State code checked against current and retired codes; the non-transport validity date is preferred.
Voter ID (EPIC)
Reads
EPIC number, name, relative's name, gender, date of birth where printed
Values are read from the English side of the bilingual card.
DPDP Act
Data handling that suits the DPDP Act
The Digital Personal Data Protection Act asks Data Fiduciaries to collect what they need, keep it only as long as needed, protect it and erase it on request. KYCVerify gives you the mechanisms; the policies and notices are yours.
Consent recorded
Each verification starts with a consent step, stored with its time, IP and user agent.
Minimisation
Last four Aadhaar digits, masked and hashed document numbers, no contact details from Aadhaar in clear.
Storage limitation
Per-app retention purges files, embeddings and identity automatically.
Erasure
Purge a session from the console or with
DELETE /v1/sessions/{id}.Security safeguards
AES-256-GCM uploads, hashed secrets, RBAC and an audit log.
No third-party verifier
Aadhaar, PAN and face checks run on KYCVerify's own engine; no identity data is sent to another verification provider.
Regulatory notes
What it is, and what it is not.
Not legal advice. These are the boundaries we design to; confirm your obligations with counsel.
Context as reported in public sources up to October 2026: UIDAI requires entities performing offline verification to register as an Offline Verification Seeking Entity (OVSE); the DPDP Rules 2025 were notified in November 2025, with most obligations applying from 13 May 2027. Check the current position before you rely on it.
- KYCVerify verifies UIDAI-signed offline artefacts. It is not Aadhaar authentication and does not use an AUA/KUA licence.
- Under UIDAI's Regulation 13A (9 Dec 2025), an entity performing Aadhaar offline verification must register as an Offline Verification Seeking Entity. KYCVerify holds no such registration and confers none; confirm your position with counsel.
- RBI, SEBI, IRDAI and DoT each define which KYC methods count for their regulated entities. Map them to workflows with your compliance team.
- PAN validation is structural; a lookup against the Income Tax Department needs a licensed provider.
FAQ
India questions.
Can Aadhaar numbers end up in our database?
Not as a field. The offline formats carry only the last four digits. If a workflow accepts a photographed Aadhaar card, the OCR path stores the masked number and a keyed fingerprint, but the encrypted card image shows the full number until the retention purge. Take aadhaar out of the document step's allowed types if you do not want card photos at all.
Where do UIDAI's certificates come from?
KYCVerify keeps UIDAI's published offline-signing certificates, including older keys that still sign older artefacts, and verifies every Secure QR and Offline e-KYC signature against them. There is nothing for you to install.
Does it support DigiLocker?
Not today. Aadhaar is handled through Secure QR and Offline e-KYC.
Verify Aadhaar the way UIDAI signs it.
Enable the Aadhaar step in the workflow builder and scan a Secure QR in the sandbox.

