Verify identity with DigiLocker
DOCEZKYC retrieves a citizen's Aadhaar, PAN and Driving Licence straight from DigiLocker using the Meri Pehchaan OAuth 2.0 flow. Choose which permissions to request, then continue to DigiLocker to sign in and approve them.
Permissions to request
Ask only for what you need. DigiLocker shows the citizen this same list on its consent screen, and only approved permissions are granted.
How the flow works
- The citizen picks permissions and is redirected to DigiLocker with a PKCE-protected authorization request.
- They sign in at DigiLocker and approve the consent screen.
- DigiLocker redirects back with a one-time code, which the server exchanges for an access token and a signed id_token.
- The server reads the issued-documents list, pulls the machine-readable XML for Aadhaar, PAN and Driving Licence, and verifies each download's HMAC.