Skip to content

KYCVerify for India

Indian identity, verified on Indian terms.

Aadhaar's offline formats are signed by UIDAI. KYCVerify verifies those signatures, validates PAN, reads Indian cards and keeps the minimum, encrypted and purged on your schedule.

Aadhaar offline formats, signature verified
2
Indian cards read by OCR
4
Aadhaar digits kept from offline artefacts
Last 4
default retention, 1 to 3,650 per app
90 days

Aadhaar Secure QR

Scan the letter. Check UIDAI's signature.

The QR on every Aadhaar letter and e-Aadhaar carries the resident's details and a 2048-bit RSA signature from UIDAI. KYCVerify verifies it against UIDAI's own certificates, including older keys that still sign older letters.

  • Decoded in the browser from the camera, or on the server from a photo.
  • Version 2 and later codes, with the last-four-mobile field, are understood.
  • Reports which certificate verified the signature.
  1. QR text

    one very large base-10 integer

  2. Big-endian bytes

    a GZIP stream (zlib accepted)

  3. Decompress and split

    fields delimited by 0xFF, then photo and hashes

  4. RSA-2048 verify

    SHA256withRSA over every byte before the last 256

  5. Record

    last 4 digits, demographics, photo

  1. indicator0-3
  2. reference idlast 4 + timestamp
  3. name · dob · genderdemographics
  4. address11 fields
  5. photoJPEG 2000
  6. hashesemail, mobile
  7. signature256 bytes
From the printed code to a signature-verified record, with no third-party service in between.

Offline e-KYC XML

The ZIP from UIDAI, verified to the byte.

Residents download a share-phrase-protected ZIP from UIDAI. KYCVerify opens it, checks the XML-DSig digest and signature, and refuses files older than your limit (3 days by default).

If the XML was edited after UIDAI signed it, the check says exactly that: the document digest does not match.

  1. ZIP + share phrase

    ZipCrypto or AES; wrong phrase is reported

  2. OfflinePaperlessKyc

    reference id, Poi, Poa, Pht, Signature

  3. Digest check

    enveloped-signature transform, C14N, compare DigestValue

  4. Signature check

    RSA PKCS#1 v1.5 over SignedInfo, UIDAI certificates only

  5. Age check

    generated within max_xml_age_days (3)

The certificate inside the XML's KeyInfo is ignored: trust comes only from the UIDAI certificates you install in certs/uidai.

Trust comes only from UIDAI's published certificates, never from the certificate the file carries.

Minimum by design

What an Aadhaar check keeps.

The offline formats never carry the full number. Card photos do, so decide with counsel whether to accept them and how they fit your Aadhaar Data Vault obligations.

Aadhaar data and how KYCVerify handles each item
DataStoredHow
Aadhaar numberLast four digitsNeither offline format contains the full number. If a workflow accepts a photographed Aadhaar card, the number is read to validate it and kept masked with a keyed fingerprint; the encrypted card image, which shows it, is purged with the session.
Name, birth date, gender, addressYes, with the sessionFrom the UIDAI-signed record. Purged with the session.
PhotoEncrypted fileJPEG 2000 (Secure QR) or JPEG (XML), AES-256-GCM at rest; used for face match.
Mobile and emailNever in clearOnly UIDAI's hashes, used to confirm an email the person typed.
Offline XML ZIPEncrypted fileKept as evidence for reviewers until the retention period ends.
Share phraseNot keptUsed once to unlock the ZIP.

PAN

Structure, holder type, name initial.

Ten characters carry more than they seem. KYCVerify checks the format, decodes the holder type and compares the fifth character with the surname. With a card photo, it reads the PAN back and compares.

Structural only. Confirming that a PAN exists and belongs to this person needs a lookup through a licensed provider, which KYCVerify does not make. Every PAN result says government_lookup: false.

  1. ABCSeriesthree letters, AAA to ZZZ
  2. PHolder typeP individual, C company, H HUF, F firm, A AOP, T trust, B BOI, L local authority, J artificial juridical, G government
  3. EName initialsurname for individuals, entity name otherwise
  4. 1234Sequencefour digits
  5. FCheck lettera letter; the algorithm is not published
An example PAN, ABCPE1234F, read position by position.

Indian cards by OCR

Read from the card, nothing invented.

Bilingual cards are read from their English side, with Hindi gender words understood. A field that cannot be found stays empty and is listed as an issue.

  • Aadhaar card / e-Aadhaar print

    Reads

    Name, date or year of birth, gender, address from the back

    Number masked to XXXX XXXX 1234; a 16-digit VID is never mistaken for it.

  • PAN card

    Reads

    PAN, name, father's name, date of birth

    Both the labelled layout (since 2018) and the older unlabelled one. OCR letter and digit confusions in the PAN are repaired.

  • Driving licence

    Reads

    Licence number, name, relative's name, date of birth, validity, address

    State code checked against current and retired codes; the non-transport validity date is preferred.

  • Voter ID (EPIC)

    Reads

    EPIC number, name, relative's name, gender, date of birth where printed

    Values are read from the English side of the bilingual card.

DPDP Act

Data handling that suits the DPDP Act

The Digital Personal Data Protection Act asks Data Fiduciaries to collect what they need, keep it only as long as needed, protect it and erase it on request. KYCVerify gives you the mechanisms; the policies and notices are yours.

  • Consent recorded

    Each verification starts with a consent step, stored with its time, IP and user agent.

  • Minimisation

    Last four Aadhaar digits, masked and hashed document numbers, no contact details from Aadhaar in clear.

  • Storage limitation

    Per-app retention purges files, embeddings and identity automatically.

  • Erasure

    Purge a session from the console or with DELETE /v1/sessions/{id}.

  • Security safeguards

    AES-256-GCM uploads, hashed secrets, RBAC and an audit log.

  • No third-party verifier

    Aadhaar, PAN and face checks run on KYCVerify's own engine; no identity data is sent to another verification provider.

Regulatory notes

What it is, and what it is not.

Not legal advice. These are the boundaries we design to; confirm your obligations with counsel.

Context as reported in public sources up to October 2026: UIDAI requires entities performing offline verification to register as an Offline Verification Seeking Entity (OVSE); the DPDP Rules 2025 were notified in November 2025, with most obligations applying from 13 May 2027. Check the current position before you rely on it.

  • KYCVerify verifies UIDAI-signed offline artefacts. It is not Aadhaar authentication and does not use an AUA/KUA licence.
  • Under UIDAI's Regulation 13A (9 Dec 2025), an entity performing Aadhaar offline verification must register as an Offline Verification Seeking Entity. KYCVerify holds no such registration and confers none; confirm your position with counsel.
  • RBI, SEBI, IRDAI and DoT each define which KYC methods count for their regulated entities. Map them to workflows with your compliance team.
  • PAN validation is structural; a lookup against the Income Tax Department needs a licensed provider.

FAQ

India questions.

Can Aadhaar numbers end up in our database?

Not as a field. The offline formats carry only the last four digits. If a workflow accepts a photographed Aadhaar card, the OCR path stores the masked number and a keyed fingerprint, but the encrypted card image shows the full number until the retention purge. Take aadhaar out of the document step's allowed types if you do not want card photos at all.

Where do UIDAI's certificates come from?

KYCVerify keeps UIDAI's published offline-signing certificates, including older keys that still sign older artefacts, and verifies every Secure QR and Offline e-KYC signature against them. There is nothing for you to install.

Does it support DigiLocker?

Not today. Aadhaar is handled through Secure QR and Offline e-KYC.

Verify Aadhaar the way UIDAI signs it.

Enable the Aadhaar step in the workflow builder and scan a Secure QR in the sandbox.