Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · October 6, 2026

DigiLocker API: how businesses verify documents in India

The DigiLocker API explained for businesses: who may register as a requester, what the user sees, the data and documents returned, Rule 9A and the PML Rules, what is not published, and the fallback for everyone else.

By DiditUpdated
digilocker-api-cover.png

In short

The DigiLocker API lets a registered business, called a requester, ask an Indian user for consent and then read identity details and government-issued documents from that user's DigiLocker account. It is an OAuth 2.0 and OpenID Connect redirect, run by India's National e-Governance Division (NeGD).[5][7]

  • Private organisations registered in India are on the eligible list. A committee reviews each application, and final approval rests with the chief executive.[6]
  • Issued documents stand at par with physical originals, and India's anti-money laundering (AML) rules accept them.[2][9][10]
  • No fee schedule, no sandbox and no onboarding lead time are published.[6][8]

Last reviewed: 5 October 2026 · Not legal advice

DigiLocker is the Indian government's document wallet: a cloud account where a citizen holds documents that ministries, states and boards issue in digital form, and from which the citizen shares them with consent.[1] For a business, one redirect returns a name, a date of birth and digitally signed documents such as a PAN record or a driving licence.

What the DigiLocker API is

DigiLocker describes itself as a secure cloud platform for storing, sharing and verifying documents, and as a flagship initiative of the Ministry of Electronics and IT (MeitY).[1] Three roles meet on it: issuers push documents to an account, the user (the "subscriber" in the rules) holds them, and requesters ask for access.[4][9]

The requester interface is the Requester Meri Pehchaan API Specification, version 2.4 of September 2026; Meri Pehchaan is the national single sign-on by DigiLocker.[7] It is not an electronic ID (eID) in the European sense, but a consented document exchange behind a sign-in.

DigiLocker

India's government document wallet and consented document exchange

On request
CountryIndia
OperatorNeGD, Digital India Corporation, MeitY[1]
LaunchedDigital Locker Rules notified on 21 July 2016; the pages we read give no launch year[9]
Users70+ crore (700 million+) registered users, site counter read in October 2026[1]
CredentialA cloud account opened with a mobile or Aadhaar number, a one-time password (OTP) and a security PIN[3]
Level of assuranceNone under eIDAS: an Indian scheme outside the EU notification system; EU recognition is only a proposal[12]
Data returnedDigiLocker ID, name, date of birth, gender, mobile, picture, email; issued documents as PDF or XML[7]
Legal basisInformation Technology Act, 2000; Digital Locker Rules, 2016; Rule 9A of 8 February 2017[9]
Didit statusAdded on request

How many people use DigiLocker

The DigiLocker home page counts 70+ crore registered users and 900+ crore issued documents. One crore is ten million: more than 700 million accounts and 9 billion documents.[1]

700 million+Registered users (site counter, October 2026)
9 billion+Issued documents
300+Issuers in Maharashtra alone

The pages we read state no share of the adult population and no count of requester transactions. A registered account may also lack the document you need: a document cannot be fetched when the issuer's database has no record of it.[3]

What the user sees

The first step is not an API call. It is a DigiLocker web page where the user signs in and authorises your application, then returns to your redirect address.[7] You never see the OTP or the PIN.

Verify your identity

Share from DigiLocker

Continue with DigiLocker

1The user chooses DigiLocker in your sign-up.

DigiLocker

Sign in

Mobile or Aadhaar number, an OTP, then your security PIN.

2DigiLocker asks for a mobile or Aadhaar number, an OTP valid for 10 minutes, and the PIN.[3]

DigiLocker

Give consent

  • Profile detailsShared
  • PAN recordShared
  • Other documentsNot shared

Allow

3The consent screen shows your service name, purpose and requested documents.[7]

Verify your identity

Documents received

4Back in your app, with an authorisation code.

Users grant consent per document or scope and can revoke it at any time.[5] The specification documents one flow, a browser redirect. The device-code calls for limited-input devices were removed in version 2.0 (15 September 2022), so no QR hand-off between devices is documented.[7]

User Your app DigiLocker Issuer
1Starts sign-up
2Authorisation redirect

The user signs in and consents on DigiLocker's page

3Authorisation code
4Code for token
5Access and ID token
6Get issued documents
7Fetch from source
8File and HMAC

Authorisation code with PKCE, then document calls.[7]

What a business receives

What comes back depends on the scopes the user approved; the token response lists them.[7]

DataWhenFormat and notes
DigiLocker IDWith the user details scopeA unique 36-character account identifier
Name, date of birth, genderWith the user details scopeDate as DDMMYYYY; gender M, F or T
Mobile, picture, emailSame scope, since version 2.4As registered with DigiLocker
Issued documentsOptional, per documentA list with type, issuer and URI; each file as PDF or XML, with an HMAC to check integrity
e-Aadhaar dataOptional, where the account has itXML only, never the PDF[7][8]
Full Aadhaar numberNot among the listed fieldsThe partner FAQ says only the last four digits can be verified[8]

Fields from the requester specification, version 2.4.[7]

The stable identifier is the DigiLocker ID, not a national number. The user details can include a picture. The specification does not list the fields of the e-Aadhaar XML; for reference, the offline XML that the Unique Identification Authority of India (UIDAI) issues directly holds name, date of birth, gender, address and a photo under UIDAI's signature.[13]

Watch out

Profile data is "as registered with DigiLocker", and an account can be opened with a mobile number alone. Check the e-Aadhaar flag (Y or N) in the user details, or rely on an issued document, before you treat a name or a date of birth as verified.[3][7]

The law behind DigiLocker

DigiLocker rests on the Digital Locker Rules, 2016, made under sections 6A, 67C and 87 of the Information Technology Act, 2000.[9] They define a requester as any State or Central department, agency "or body corporate" requesting access to a subscriber's records, which is the door for private companies.

Rule 9A(1)Digital Locker Rules, 2016, as amended on 8 February 2017

"Issuers may start issuing and Requesters may start accepting digitally (or electronically) signed certificates or documents shared from subscribers’ Digital Locker accounts at par with the physical documents in accordance with the provisions of the Act and rules made thereunder."

Source: Digital Locker Rules and Amendment, G.S.R. 711(E) and G.S.R. 111(E)[9]

The rule lets requesters accept; it does not order them to.[9]

Does DigiLocker satisfy AML customer due diligence

For reporting entities under the Prevention of Money-laundering Act, the answer sits in the Maintenance of Records Rules, 2005 (the PML Rules), which name the digital locker in a definition.

Rule 2(1)(cb)Prevention of Money-laundering (Maintenance of Records) Rules, 2005

"'equivalent e-document' means an electronic equivalent of a document, issued by the issuing authority of such document with its valid digital signature including documents issued to the digital locker account of the client as per rule 9 of the Information Technology (Preservation and Retention of Information by Intermediaries Providing Digital Locker Facilities) Rules, 2016;"

Source: PML (Maintenance of Records) Rules, 2005, Financial Intelligence Unit India[10]

Rule 9(4) lets an individual client submit an officially valid document "or the equivalent e-document thereof", and the same wording covers the Permanent Account Number (PAN). Rule 9(15)(c) sets the condition: the reporting entity "shall verify the digital signature" and "take a live photo" as Annexure 1 specifies.[10] So a DigiLocker document is an accepted identity document, not a full due-diligence file.

The Reserve Bank of India (RBI), in its Know Your Customer (KYC) FAQ of 9 June 2025, lists DigiLocker among the digital channels for non-face-to-face onboarding.[11]

How a business connects to the DigiLocker API

There is no licence class like the one for Aadhaar authentication, which our Aadhaar eKYC guide covers. A business registers as a requester, and NeGD decides.

RequirementWhat the procedure says
Who may applyOrganisations registered in India, private companies included, with experience of online services for Indian citizens
Proof of the entityA nodal officer authenticates with Aadhaar OTP; company and tax numbers are verified; a digital signature is required
ApprovalA manager, then a committee, then the chief executive; terms of use signed on the portal
After go-liveA quarterly usage report and an STQC audit report of the application
Foreign firmsAn Indian mobile number and a server located in India are mandatory (partner FAQ, 24 March 2025)[8]

From the partner onboarding procedure of 5 June 2024.[6]

Credentials come from the government's API Setu partner portal.[5][8] Three things are not published in the documents we read: a fee schedule, an onboarding lead time and a sandbox. The committee meets weekly, "no requests of temporary access for any testing purpose" are entertained, and the partner FAQ says there is no separate test environment.[6][8]

Direct

Register as a requester

  • Your name on the consent screen
  • Your own approval and audit

Partner onboarding procedure

Through a provider

Use a provider's DigiLocker check

  • One contract with the provider
  • No public rule on resale found

Confirm the terms with NeGD

Without the API

Document route

  • Works for every user
  • ID capture, liveness, face match

Your own verification flow

A provider's DigiLocker check is the second route. We found no public rule on sub-licensing requester access, so ask any provider in writing how its access is approved for your use case. See also what eID verification is and the eID schemes by country.

Use cases and sector rules

DigiLocker names banks, government agencies and educational institutions as typical requesters.[5]

  • KYC and AML onboarding: an issued document is an equivalent e-document under the PML Rules.[10]
  • Driving checks: the road transport ministry recognised DigiLocker for digital driving licences and registration certificates on 8 August 2018.[3]
  • Age checks: the user details include a date of birth.[7] According to dpdpa.com, Rule 10 of the Digital Personal Data Protection Rules 2025 allows a virtual token mapped to age details, for example through DigiLocker, for parental consent.
  • Signing: uploaded documents can be digitally signed with the eSign facility.[7]

We found no DigiLocker-specific rule for gambling or telecom in these sources. The Aadhaar and Other Laws (Amendment) Act, 2019 allows voluntary use of Aadhaar for SIM cards and bank KYC, but that concerns Aadhaar, not DigiLocker.[14]

Limits and fallbacks

DigiLocker is wide, not universal.

  • Non-residents and foreigners. Sign-up needs a mobile or Aadhaar number, and registration takes an Indian mobile number only, so a non-resident Indian with a foreign number cannot sign up.[3]
  • Minors. No minimum age is stated. Student accounts were created from mobile numbers shared by the school board, so do not assume the holder is an adult.[3]
  • Missing documents. If the record is not in the issuer's database, the document cannot be fetched.[3]
  • Outages. The FAQ admits delayed OTPs and a "UID service temporarily unavailable" error.[3]
  • Data protection. The Aadhaar PDF is withheld under data protection rules, and rate limits apply without published numbers.[3][8]

On security, DigiLocker lists encryption in transit, multi-factor sign-in, ISO 27001 certified hosting and audits by CERT-In empanelled agencies.[3] The fallback for everyone else is the document route: capture of a passport or national ID, reading the Near Field Communication (NFC) chip where the document has one, a liveness check and a face match.

1Offer DigiLocker first

Does the user have DigiLocker and the document

Yes

Consent and fetch

Check the signature, take a live photo.

No

Verify with a document

Capture, chip reading, liveness and face match.

2Screen and decide

The decision stays with you.

DigiLocker first, a document for everyone else.

DigiLocker integration checklist

  • Confirm your entity is registered in India and can host on a server in India.[6][8]
  • Write the use case exactly as you will build it; "no deviation shall be allowed".
  • Obtain a digital signature for the organisation.[6]
  • Register on the API Setu partner portal and set the exact redirect address.[5][8]
  • Generate a new PKCE code verifier for every authorisation request.[7][8]
  • Request only the document types you need.[7]
  • Compare the HMAC of every downloaded file with the header value.
  • Store the DigiLocker ID and the last four Aadhaar digits at most, never the full number.[8][14]
  • Build the document fallback before launch.

Note

A concept note of 29 July 2026 on the DigiLocker site proposes that DigiLocker present credentials to European relying parties with OpenID for Verifiable Presentations (OpenID4VP). It puts bilateral legal recognition first.[12] For the European side, see the EU Digital Identity Wallet page.

How Didit helps with DigiLocker and eID verification

Didit adds DigiLocker on request. In India today, Didit runs the document route: ID verification of Indian and foreign documents, NFC chip reading where the document carries a chip, liveness and face match, plus AML screening. A full KYC check costs $0.33, AML screening $0.20 and NFC verification $0.15.

That route also covers non-residents and foreigners. For the eIDs Didit runs in Europe, the documentation shows what lands on the session.[15] Our post on Aadhaar database validation covers the number-check side.

Didit provides

  • Document verification, liveness and face match in India today
  • AML screening and ongoing monitoring
  • The evidence of every check

Stays with you

  • Your requester registration and approval with NeGD
  • The live photo and signature checks your rules require
  • The risk assessment and the onboarding decision

Bring DigiLocker to your sign-up

Tell us your use case in India, and start with the document route today.

Talk to us about DigiLockerStart free

Key takeaways

  • The DigiLocker API is an OAuth 2.0 redirect: the user consents on DigiLocker's page, and you receive profile details and issued documents.
  • Private organisations registered in India are eligible to apply as requesters; a committee reviews each application.
  • Rule 9A puts shared documents at par with physical ones, and the PML Rules accept them as equivalent e-documents with a signature check and a live photo.
  • Users without an Indian mobile number need a document fallback.

Frequently asked questions

Can a private company use the DigiLocker API?

Yes, if approved. The Digital Locker Rules define a requester to include a body corporate, and the onboarding procedure lists private organisations registered in India as eligible. A foreign firm also needs an Indian mobile number and a server in India.[6][8][9]

How much does the DigiLocker API cost?

No fee schedule is published in the DigiLocker pages, the onboarding procedure or the API specification we read in October 2026. Ask NeGD during onboarding.[6][7]

What data does DigiLocker return?

A DigiLocker ID, name, date of birth, gender, and since version 2.4 mobile, picture and email. With document scopes, each issued document as PDF or XML. The full Aadhaar number is not among the listed fields.[7][8]

Is a DigiLocker document valid for KYC in India?

Yes, with conditions. The PML Rules define an equivalent e-document to include documents issued to the client's digital locker account. The reporting entity must verify the digital signature and take a live photo.[10][11]

What level of assurance does DigiLocker have?

None in the European sense: levels of assurance belong to the EU's eIDAS regulation, and DigiLocker is an Indian scheme outside it. Sign-in uses an OTP together with a security PIN.[3][12]

Can foreigners or non-resident Indians use DigiLocker?

Registration takes an Indian mobile number only, so a non-resident Indian cannot sign up with a foreign number. Use a document check for them.[3]

Can minors have a DigiLocker account?

No minimum age is stated in the pages we read. Accounts were created for school students, so an account does not prove adulthood. Read the date of birth instead.[3][7]

Is there a DigiLocker sandbox for testing?

None is documented. The onboarding procedure says requests for temporary testing access are not entertained, and the partner FAQ says there is no separate environment.[6][8]

How long does DigiLocker integration take?

No lead time is published. The onboarding procedure covers identification, evaluation, verification, the agreement, technical integration, testing and launch.[6]

Sources

  1. DigiLocker home page, National e-Governance Division, user and document counters read in October 2026.
  2. About DigiLocker, National e-Governance Division.
  3. DigiLocker frequently asked questions, National e-Governance Division.
  4. DigiLocker Partner Integration, introduction, National e-Governance Division.
  5. DigiLocker Partner Integration, requester, National e-Governance Division.
  6. Partner Organisation Onboarding Standard Operating Procedure for DigiLocker, NeGD, 5 June 2024.
  7. Requester Meri Pehchaan API Specification, version 2.4, NeGD, September 2026.
  8. FAQs during video conference with entities, partners and organisations, DigiLocker, updated to 24 March 2025.
  9. Digital Locker Rules, 2016 (G.S.R. 711(E)) and Amendment Rules, 2017 (G.S.R. 111(E)), Gazette of India.
  10. Prevention of Money-laundering (Maintenance of Records) Rules, 2005, Financial Intelligence Unit India.
  11. FAQs on the Master Direction on KYC, Reserve Bank of India, 9 June 2025.
  12. Digital Wallet Interoperability Framework with Global Sovereign Nations, concept note, published on digilocker.gov.in, 29 July 2026.
  13. Aadhaar Paperless Offline e-KYC, Unique Identification Authority of India.
  14. Aadhaar and Other Laws (Amendment) Act, 2019, Gazette of India.
  15. Digital ID wallets, Didit documentation.

Compare DigiLocker with other national schemes on the eID verification page.

One workflow for India and beyond

Verify documents today, and add schemes as you grow.

Start freeTalk to us

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page