Skip to content

Telecom and SIM activation

Bind a SIM to a present, verified person.

SIM activation needs proof that the subscriber is real and present. KYCVerify pairs a document or signed Aadhaar artefact with active liveness and a face match to the portrait, and keeps the evidence encrypted until your retention period ends.

Recommended workflowTelecom and SIM
  1. 1Consent
  2. 2Aadhaar
  3. 3Liveness

At submit

  • Face match against the Aadhaar photo
  • Duplicate detection
  • Age (18+)
steps at the counter or on the phone
3
UIDAI-signed photo to match against
1
minimum age, configurable
18

decision.auto_decline: true · a failed check declines

The problem

What this use case needs from verification.

  • Presence

    Active challenges require the subscriber to move on camera; frames are checked for one, consistent face.

  • Binding

    Face match compares the live selfie with the document portrait or the UIDAI-signed photo.

  • Repeat activations

    Duplicate detection flags one face activating many subscriptions.

Recommended workflow

Steps the person sees, checks that decide.

A second workflow with the document step instead of Aadhaar serves subscribers who present a passport or another card. Duplicate review lets you apply your own rule for how many connections one person may hold.

In the hosted flow

  1. 1Consent
  2. 2Aadhaar
  3. 3Liveness

At submit

  • Face match against the Aadhaar photo
  • Duplicate detection
  • Age (18+)
  • IP recorded for the audit trail

Keys left out of the config keep their defaults. Paste it into the workflow builder, or read every key on the workflows page.

Workflow config · json
{
  "steps": {
    "document":   { "enabled": false },
    "aadhaar":    { "enabled": true, "methods": ["secure_qr", "offline_xml"] },
    "liveness":   { "enabled": true, "challenges": 3 },
    "face_match": { "enabled": true },
    "duplicate":  { "enabled": true },
    "age":        { "enabled": true, "min_age": 18 },
    "aml":        { "enabled": false }
  }
}

Signals

What happens when something is off.

Real cases for this industry, the check that sees each one and what the engine records. Codes are exactly as they appear in the decision.

Signals and outcomes
WhenSeen byOutcome
A photo of the subscriber is shown to the cameralivenessattempt failschallenge_failed or frames_identical
Someone else's Aadhaar QR is scannedface_matchfailedface_match_failed
One person activates many connectionsduplicatereviewduplicate_found
Only a birth year is on the Aadhaar record, and it straddles 18agereviewage_uncertain
The QR's signature does not verifyaadhaarfailedaadhaar_signature_invalid

Regulatory context

Where the rules meet the product.

Subscriber verification in India is tightly specified. KYCVerify can support a verification you design; it does not stand in for the prescribed process. This is context, not legal advice.

Not legal advice. KYCVerify does not certify compliance with any law or regulator. Confirm how each rule applies to you with your compliance team and counsel.

  • Telecommunications Act, 2023

    Requires authorised entities to identify the people they serve through verifiable biometric-based identification, with the method prescribed by the government. KYCVerify's face match is not Aadhaar biometric authentication.

  • Department of Telecommunications instructions

    Name the documents and processes that count for subscriber verification and cap the connections one person may hold. Duplicate detection helps you see repeat activations; the rule is yours to apply.

  • Digital Personal Data Protection Act, 2023

    Applies to subscriber identity data as to any personal data. Per-app retention and on-demand purges keep what you hold to what the purpose needs.

What KYCVerify does not settle for you

  • Indian telecom subscriber verification follows the Department of Telecommunications' instructions, which name the methods that count. KYCVerify does not provide Aadhaar biometric or OTP authentication through an AUA/KUA.
  • Liveness is active challenge-response, not certified PAD.

Integrate

One call starts it.

A short expires_in_hours suits a counter: the link is opened on the store tablet and expires before the shift ends.

  1. 1Create the session with this workflow and your own reference.
  2. 2Send the person the url, or open it on a device you control.
  3. 3Act on the signed session.status_updated webhook.

Create a session

curl -X POST https://kycverify.me/api/v1/sessions \
  -H "x-api-key: $KYC_API_KEY" \
  -H "content-type: application/json" \
  -d '{
    "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
    "vendor_data": "msisdn-request-7781",
    "metadata": {
      "store": "BLR-KRM-04",
      "channel": "retail"
    },
    "expires_in_hours": 2
  }'

201 Created

{
  "session_id": "ses_0k3v9x2m4a7qhd8f1rtb",
  "status": "not_started",
  "url": "https://kycverify.me/verify/q3Xf…",
  "session_token": "q3Xf…",
  "workflow_id": "wf_0k3t1c8n5e2wpzr6g4ya",
  "vendor_data": "msisdn-request-7781",
  "expires_at": "2026-10-03T11:12:44Z"
}

FAQ

Questions.

Does it work in a retail store?

Yes. Staff can create a verification link in the console and open it on the store's tablet or the subscriber's phone.

Build this workflow in the sandbox.

Set up the configuration above in the workflow builder and run a test session in minutes, then talk to us about going live.