deepidv Logo

Developer reference

Canada ID verification API: SIN structure, photo ID and FINTRAC methods

Canada has no national ID card. A reporting entity proves identity with government-issued photo ID, a Canadian credit file, or two independent reliable sources, the methods FINTRAC sets out. The Social Insurance Number has nine digits with a Luhn check digit, and it is a tax and benefits number, not an identity document. The deepidv verification API authenticates the photo ID, matches the face to it live, and runs the method your program needs.

Last reviewed October 2026

Structure of the 9-digit SIN

Social Insurance Number fields by position
DigitsFieldImplementation notes
1Region or status of first registrationSee the code list below. A 9 marks a temporary resident.
2-8SerialNo readable meaning.
9Check digitLuhn (mod 10). Catches any single-digit error and most adjacent transpositions.

A SIN that passes Luhn is well formed, not valid. Service Canada does not offer private businesses a SIN lookup, so structure is the most a SIN can tell you.

First-digit codes

  • 1 Nova Scotia, New Brunswick, Prince Edward Island, Newfoundland and Labrador
  • 2, 3 Quebec
  • 4, 5 Ontario
  • 6 Manitoba, Saskatchewan, Alberta, Northwest Territories, Nunavut
  • 7 British Columbia, Yukon
  • 9 Temporary residents (the SIN carries an expiry date)
  • 0, 8 Not assigned to individuals

These first-digit assignments follow Service Canada's registration regions.

Response contents of a Canada ID verification API

A parse result tells you whether a number is well formed. A verification response tells you whether the person in front of the camera owns it. deepidv runs one session: document capture with OCR and the AI document fraud check, face liveness with a 1:1 match to the document photo, the FINTRAC method you select (photo ID, credit file or dual-process), PEP and sanctions screening, and an optional 1:N match that flags the same face behind a second account.

  • One decision per session, with an outcome for every step, delivered by webhook (session.status.verified, session.status.rejected, session.status.failed).
  • A reason for every non-pass outcome, separating malformed input, a record that was not found, a mismatch between document and record, and a registry that did not answer.
  • A signed verification receipt with a UTC timestamp per step, anchored on Base L2 with zero personal data on chain, checkable at proof.deepidv.com.

Capturing provincial photo ID and passports

Provincial driver's licences and photo cards are bilingual in places and carry a PDF417 barcode on the back that encodes the front-side data; deepidv reads both sides and flags a mismatch between them. Canadian passports carry a chip that NFC reading checks against the issuing country's signature. Capture is a single shot, with document liveness and fraud detection from a 3D mesh check rather than a tilt sequence.

Credit file and dual-process checks

FINTRAC accepts a Canadian credit file that has existed for at least three years, with the name, address and date of birth matching what the person provided. The dual-process method takes two of three confirmations from different reliable sources: name and address, name and date of birth, or name and a confirmed financial account. deepidv runs the credit file check as a workflow step and records which source confirmed which field, the record FINTRAC expects you to keep.

Liveness and FINTRAC's photo ID method

For remote onboarding, FINTRAC's guidance accepts technology that authenticates a government-issued photo ID and compares the person, live, to the photo on it. deepidv runs passive face liveness and a 1:1 match in the same session as capture, so the authenticity result and the face comparison carry one timestamp. The same session can add deepidv's checks against injected video, the attack a remote photo ID method is most exposed to. Under PIPEDA the Privacy Commissioner advises against using the SIN as a general identifier, so deepidv workflows never require it for identity.

How deepidv runs Canada verification

deepidv is a verification engine and agentic compliance suite built from the ground up, without third-party verification APIs underneath. The engine is SOC 2, ISO 27001 and PCI DSS certified, and deepidv is a member of DIACC and the AVPA. Luna, the verification agent, builds and sends Canada verification workflows from the platform or from any LLM through MCP. Arbiter, the compliance agent, maps the workflow to FINTRAC requirements, monitors accounts after onboarding and drafts suspicious transaction reports for FINTRAC for your team to review.

Frequently asked questions

Can a SIN be verified against a government database?

No. Service Canada does not offer private businesses a SIN lookup. A SIN can be checked for structure (nine digits, a valid first digit, a passing Luhn check), and identity is proven with one of FINTRAC's methods.

What does a SIN starting with 9 mean?

It was issued to a temporary resident, such as a student or worker on a permit, and it expires with that status.

How old must a credit file be for FINTRAC's credit file method?

At least three years, and it must come from a Canadian credit bureau.

Can I verify identity remotely under FINTRAC rules?

Yes. The photo ID method works remotely when technology authenticates the document and the person is compared live to its photo.

Do I need to collect the SIN to verify a customer?

No. Collect it only where a law requires it, such as reporting interest income.

API documentation

Read the endpoints, field names and webhook events in the docs, or book a call to scope Canada verification for your product.

Related pages