Nafath integration: a guide for businesses in 2026
How a business integrates Nafath, Saudi Arabia's national sign-in: what users see, what the official sources say you receive, the SAMA rule for remote onboarding, private access, unpublished costs and a document fallback.

In short
A Nafath integration lets your platform sign people in with Saudi Arabia's unified national access system: the user types a national ID or Iqama number, then approves the request in the Nafath app. SDAIA's user guide documents that approval as picking a matching number and entering a PIN.[1] Private platforms are in scope, and the Saudi Data and AI Authority (SDAIA) runs the system.[1][2]
- More than 23.5 million users and 530 connected platforms (November 2024).[2]
- For remote account opening, the Saudi Central Bank requires the institutions it supervises to use biometric authentication "with a high level of verification or above".[3]
- Fees, the attribute list and onboarding lead times are not published.
Nafath integration means adding "Sign in with Nafath" to a website or app, so a person in Saudi Arabia proves who they are with the national system instead of a photo of a card. The official material is thin: everything below comes from four official sources, read on 5 and 6 October 2026, and where they are silent this guide says so.
What Nafath is
Nafath is Saudi Arabia's unified national access system, an electronic identification (eID) scheme: one sign-in that people use across government and private digital services.[2] SDAIA's user guide describes it as "a national platform that allows users to sign-on to various public and private sector platforms safely and securely by using unique electronic identifiers that are based on international standards".[1]
Nafath
Saudi Arabia's unified national access system
Nafath is often confused with Absher. Absher's own site describes it as the Ministry of Interior's electronic platform, providing services to citizens, residents and visitors.[4] Nafath's password login uses the password of the person's Absher account, which the guide calls the "Digital Identity (Absher)".[1]
Adoption: users, operations and platforms
The most recent official figures we found come from the Saudi Press Agency, quoting the director of SDAIA's National Information Center on 28 November 2024.[2]
Saudi Press Agency, 28 November 2024.[2]
Note
Higher user counts for 2026 circulate in vendor guides. We could not trace them to an SDAIA publication. No official share of the adult population is published.
For how it compares with other state sign-ins, see national digital identity worldwide.
What the user sees
SDAIA's user guide documents two ways to log in: through the Nafath app, or with a username and password.[1] The screens below redraw the guide's app route, not the live app.
Sign in with Nafath
Enter your National ID or Iqama number.
Login
1In the guide, the user enters their ID number and presses Login.[1]
Your request number
47
Open the Nafath app to complete the login.
2The guide then shows a request number on the screen.[1]
Incoming request
A service is asking to sign you in.
Accept
Reject
3In the guide, the request shows in the app, to accept or reject.[1]
Pick the matching number
12 · 47 · 83
Choose the number your service is showing.
4The guide shows three numbers; the user selects the one that matches.[1]
Enter your PIN
The six-digit code you created in the app.
5Per the guide, the user enters the PIN and the app confirms the request was accepted.[1]
Guide-documented screens, subject to change. The numbers shown are illustrative.[1]
The guide describes one flow: the service shows the request number and the approval happens in the Nafath app.[1] The second route needs no app: the user enters their ID number and Absher password, then a one-time code sent to the mobile number of their Absher account.[1]
The request appears in the Nafath app
Simplified. Steps 1, 3 and 4 come from the user guide; the server interface behind steps 2 and 5 is not published.[1]
Each error the guide lists is a state your sign-in page has to handle.
| Situation | What the guide says[1] | What to build |
|---|---|---|
| Request timeout | The user must accept within 60 seconds of submitting, then start a new request from the service | A visible countdown and a "try again" button |
| Wrong number picked | An error appears; the user must go back to the service and submit a new request | A clear instruction to compare the numbers first |
| Wrong PIN | The user re-enters the six-digit code created in the app | Nothing on your side: the PIN never reaches you |
| Wrong password | The username is the National ID or Iqama number; the password is reset through Absher | A link to the other login route |
Watch out
The published guide shows a PIN step. The central bank circular refers to Nafath's biometric authentication, which the guide does not show.[1][3] Confirm the current screens with the operator before you write help text.
What a business receives
Neither SDAIA's user guide nor the central bank circular lists the attributes a connected platform gets back.[1][3] Compare the published lists in the UAE PASS integration and Singpass and Myinfo guides.
| Item | What the official sources say | Status on 5 October 2026 |
|---|---|---|
| Identifier | The user signs in with a National ID number or an Iqama number[1] | Documented |
| Request outcome | A request is accepted, rejected or expires after 60 seconds[1] | Documented |
| Name, date of birth, address, portrait | Not listed in the sources reviewed | Not published |
| Identifier format | Not specified in the sources reviewed | Not published |
Plan for the narrow case: a confirmed sign-in tied to an ID number. If onboarding needs a date of birth, an address or a face image, collect it in a second step.
Legal standing and anti-money laundering rules in Saudi Arabia
The clearest legal anchor is in financial services. On 26 November 2022 the Saudi Central Bank (SAMA) issued circular No. 44037856, "Biometric Authentication for Remote Customer Relationship Initiation/Establishment", in force.[3] It builds on SAMA's earlier instructions to identify and verify individual customers with "documents, data, or information from a reliable and independent source" when a relationship starts remotely.[3]
Circular No. 44037856Saudi Central Bank, 26 November 2022
"financial institutions are required to adopt this feature when initiating/establishing a relationship "remotely",with a high level of verification or above."
Source: SAMA Rulebook[3]
"This feature" is the biometric authentication added to "the verification mechanism for users of the (Nafath) application".[3] So for a firm SAMA supervises, biometric authentication at that level is required for anti-money laundering (AML) customer due diligence at remote onboarding, and the circular ties it to the Nafath application.[3]
| Point | What the circular says[3] |
|---|---|
| Who it binds | Financial institutions under SAMA's supervision |
| What is required | Biometric authentication "with a high level of verification or above", a feature the circular ties to the Nafath application |
| How to connect | Complete integration "with the approved service provider" |
| Deadline | Before 31 January 2023 |
| If ignored | SAMA "will take regulatory actions in case of non-compliance" |
Two limits apply. The circular text we read covers how identity is authenticated, and nothing in it states that a Nafath sign-in completes customer due diligence, so treat risk assessment, screening and monitoring as separate duties. The sources reviewed also do not cover the law that founded Nafath or Saudi data protection rules, so confirm retention and data location with local counsel.
How to connect: Nafath integration for private companies
Private companies may use Nafath. The user guide speaks of "public and private sector platforms", and SDAIA describes the system as verifying the identities of beneficiaries of "both government and private digital services".[1][2] India, by contrast, licenses access by category, as the Aadhaar eKYC guide explains.
On 5 October 2026 the official sources reviewed give no public developer portal, contract template, integration fee, per-sign-in fee, certification scheme or onboarding lead time. A business has three practical routes.
Route 1
Onboard with the operator
- SDAIA develops and operates Nafath[2]
- Connected platforms appear to users as integrated service providers[1]
- Requirements, contract and fees are not published
Ask SDAIA directly
Route 2
Approved service provider
- The route SAMA names for financial institutions[3]
- The circular does not list the approved providers
- Prices and lead times are not published
SAMA circular No. 44037856
Route 3
Document route
- Needs no agreement with the scheme
- Chip reading, liveness and face match
- Does not replace the biometric authentication SAMA requires[3]
Works for every user
Use cases and sector rules
The sources document one sector rule that names Nafath: the central bank's.
| Use case | What is documented |
|---|---|
| Know your customer (KYC) and AML onboarding in finance | Biometric authentication is required for remote onboarding by SAMA-supervised institutions[3] |
| Sign-in to private digital services | In scope: more than 530 government and private platforms were connected in November 2024[2] |
| Age checks | No published attribute list, so a date of birth cannot be assumed |
| Telecom onboarding | No sector rule in the sources reviewed |
| Electronic signing | The user guide covers sign-in only[1] |
The sources neither list a date of birth nor rule it out. Until the operator confirms it, take it from an identity document.
Limits and fallbacks
Nafath's login names two identifiers: the National ID number and the Iqama number.[1] Residents who hold an Iqama number are therefore covered alongside citizens. Anyone with neither has no documented way in. The sources state no minimum age.
The app route also depends on the moment: the user has 60 seconds to accept, and a wrong number ends the attempt.[1] The sources reviewed mention no outages or security incidents, but offer a second route anyway.
That is the document route: the user photographs an identity document, the chip is read over near-field communication (NFC) where the document has one, and a liveness check and face match tie the document to the person holding it.
1Offer Nafath first
Ask for the National ID or Iqama number.
The user holds a Saudi ID number and can approve in time
Nafath sign-in
Number match and PIN in the app.
Document route
Chip reading, liveness and face match.
2Screen and decide
The onboarding decision stays with you.
eID first, document as the fallback. A SAMA-supervised firm must still meet the circular for remote onboarding.[3]
Nafath integration checklist
- Confirm whether SAMA supervises you; if so, the circular applies to remote onboarding.[3]
- Ask SDAIA or the approved service provider for the onboarding requirements in writing.
- Request the attribute list and the identifier format before you design your database.
- Request the fee schedule, the contract terms and a test environment.
- Build both login routes the guide documents: the app and the password with a one-time code.[1]
- Show the request number clearly and add a 60-second countdown.[1]
- Handle rejected, expired and mismatched requests with a new request.[1]
- Add a document route for users without a National ID or Iqama number.
How Didit helps with eID verification in Saudi Arabia
Didit adds Nafath on request. For users in Saudi Arabia today, Didit verifies people with the document route: ID verification with NFC chip reading, liveness and face match, plus AML screening against 1,300+ sanctions, PEP and watchlists, in one workflow. A full KYC check costs $0.33 and AML screening $0.20.
The national eIDs Didit runs today are listed under digital ID wallets and in the documentation.
Didit provides
- Document checks with NFC chip reading, liveness and face match
- AML screening against sanctions, PEP and watchlists
- The evidence of every check
Stays with you
- Meeting the SAMA circular where it binds you
- The risk assessment and the policies
- The onboarding decision
Bring Nafath to your sign-up
Tell us how your users in Saudi Arabia sign in, and start with the document route today.
Key takeaways
- Nafath is Saudi Arabia's unified national access system, with more than 23.5 million users in November 2024.
- Per SDAIA's user guide, the user enters an ID number, picks the matching request number in the app and enters a PIN within 60 seconds.
- SAMA requires biometric authentication "with a high level of verification or above" when the institutions it supervises open relationships remotely.
- Private platforms can connect, but fees, attributes and lead times are not published, so keep a document route.
Frequently asked questions
How much does Nafath integration cost?
No price is published. None of the official sources reviewed on 5 October 2026 states an integration fee or a per-sign-in fee.[1][3]
Can a private company integrate Nafath?
Yes. SDAIA's user guide describes Nafath as a sign-on to "public and private sector platforms", and more than 530 government and private platforms were connected in November 2024.[1][2]
What data does Nafath return to a business?
The official sources do not publish an attribute list. They show that the sign-in is tied to a National ID or Iqama number and that a request is accepted, rejected or timed out.[1]
What is the difference between Nafath and Absher?
Nafath is the unified national access system that SDAIA operates for signing in to other services. Absher is the Ministry of Interior's own services platform. Nafath's password login uses the Absher account password.[1][2][4]
Is Nafath mandatory for remote bank onboarding?
Yes, for institutions SAMA supervises. Circular No. 44037856 requires biometric authentication "with a high level of verification or above" when a relationship starts remotely, and ties that feature to the Nafath application. Integration was due before 31 January 2023.[3]
Can foreign residents with an Iqama use Nafath?
Yes. The login accepts a National ID number or an Iqama number as the username. People who hold neither have no documented route and need a document check instead.[1]
Can minors use Nafath?
The official sources reviewed do not state a minimum age. Do not rely on Nafath as an age check until the operator confirms who can hold an account and whether a date of birth is returned.
What level of assurance does Nafath have?
Nafath has no eIDAS level of assurance, because it is a Saudi scheme and is not notified in the EU. The Saudi Central Bank uses its own wording: "a high level of verification or above". Firms SAMA supervises work to that circular; others should ask the operator what level a sign-in asserts.[3]
How long does a Nafath integration take?
No onboarding lead time is published. The only timing in the official material is on the user side: a request must be accepted within 60 seconds.[1]
Is there a Nafath test environment?
The public sources do not describe a sandbox or test accounts: the user guide covers the user's screens and the circular covers financial institutions. Ask the operator or the approved service provider for one during onboarding. Until then, build the timeout, rejected-request and wrong-number states the guide documents.[1][3]
Sources
- Nafath Platform User Guide, Saudi Data and AI Authority (SDAIA), read 6 October 2026.
- SDAIA Official: Unified National Access Contributes to Unprecedented Digital Transformation in the Kingdom, Saudi Press Agency, 28 November 2024.
- Biometric Authentication for Remote Customer Relationship Initiation/Establishment, circular No. 44037856, Saudi Central Bank (SAMA) Rulebook, 26 November 2022, in force.
- Absher, Ministry of Interior, read 6 October 2026.
Compare every national eID on the eID verification page, start with what eID verification is, and see how the European model differs on the EUDI Wallet page.
One workflow for users in Saudi Arabia and everywhere else
Verify documents with chip reading and liveness today, and add national eIDs as you need them.
Related articles
- Cl@ve integration in Spain: who can connect and what to use instead
- PhilSys verification: how businesses check the National ID
- OpenID4VP verifier guide: accepting the EUDI Wallet
- eIDAS regulation explained: what eIDAS 2 (2024/1183) changes
- Smart-ID API: a developer's guide to RP API v3
- National digital identity worldwide: models, leaders, standards