Developer reference
India Aadhaar and PAN verification API: number structure, Verhoeff check and KYC rules
India's two KYC identifiers work differently. Aadhaar is a twelve-digit number from UIDAI whose last digit is a Verhoeff check digit. PAN is a ten-character code from the Income Tax Department whose fourth character tells you what kind of holder it belongs to. Both can be validated offline for structure, and both have strict rules on how they are verified and stored. The deepidv verification API validates both, reads the signed Aadhaar QR and matches the face live.
Last reviewed October 2026
Structure of Aadhaar and PAN
| Digits | Field | Implementation notes |
|---|---|---|
| 1 | First digit | Never 0 or 1, so a valid number begins 2 to 9. |
| 2-11 | Random digits | No date, region or gender. |
| 12 | Check digit | Verhoeff algorithm, which catches all single-digit errors and adjacent transpositions. |
| Characters | Field | Implementation notes |
|---|---|---|
| 1-3 | Alphabetic series | AAA to ZZZ. |
| 4 | Holder type | See the code list below. |
| 5 | Name initial | First letter of the surname for individuals, of the name for other holders. |
| 6-9 | Sequential number | Four digits. |
| 10 | Check character | Alphabetic. |
PAN holder-type codes
- P Individual
- C Company
- H Hindu undivided family
- F Firm or LLP
- A Association of persons
- B Body of individuals
- T Trust
- L Local authority
- J Artificial juridical person
- G Government
A retail onboarding flow that accepts a PAN whose fourth character is not P is onboarding a business as a person.
Response contents of an India verification API
A parse result tells you whether a number is well formed. A verification response tells you whether the person in front of the camera owns it. deepidv runs one session: document capture with OCR and the AI document fraud check, face liveness with a 1:1 match to the document photo, PAN verification and the Aadhaar check your licence allows, PEP and sanctions screening, and an optional 1:N match that flags the same face behind a second account.
- One decision per session, with an outcome for every step, delivered by webhook (session.status.verified, session.status.rejected, session.status.failed).
- Fields as printed on the document, with a normalized Latin form in its own field where the document uses another script.
- A reason for every non-pass outcome, separating malformed input, a record that was not found, a mismatch between document and record, and a registry that did not answer.
- A signed verification receipt with a UTC timestamp per step, anchored on Base L2 with zero personal data on chain, checkable at proof.deepidv.com.
Capturing Aadhaar, the secure QR and PAN
The Aadhaar letter, card and e-Aadhaar carry a secure QR code signed by UIDAI. deepidv verifies the signature offline, which proves the data came from UIDAI without an online call. Fields appear in English and a regional script; deepidv returns both, with the Latin form in its own field. Use masked Aadhaar, where the first eight digits are hidden, whenever you do not need the full number.
Aadhaar and PAN record checks
Online Aadhaar authentication and e-KYC are open only to entities licensed by UIDAI, or through one. Offline paths, such as the signed QR, the Aadhaar paperless offline e-KYC XML with a share code, and DigiLocker, work without that licence. PAN verification confirms the PAN is valid, the name on record, and whether it is operative: PANs not linked to Aadhaar became inoperative from July 1, 2023. deepidv runs the offline Aadhaar QR, the offline e-KYC XML, DigiLocker and PAN verification live, and confirms each path with you before enabling it.
Liveness, V-CIP and RBI rules
RBI's Master Direction on KYC allows Video based Customer Identification Process (V-CIP) for remote onboarding, run live by an official of the regulated entity with liveness checks, geotagging and recording. deepidv supplies the liveness result, face match and document checks the official relies on, and records every step with a timestamp. Personal data handling falls under the Digital Personal Data Protection Act 2023.
How deepidv runs India verification
deepidv is a verification engine and agentic compliance suite built from the ground up, without third-party verification APIs underneath. The engine is SOC 2, ISO 27001 and PCI DSS certified, and deepidv is a member of DIACC and the AVPA. Luna, the verification agent, builds and sends India verification workflows from the platform or from any LLM through MCP. Arbiter, the compliance agent, maps the workflow to RBI's Master Direction on KYC requirements, monitors accounts after onboarding and drafts suspicious transaction reports for FIU-IND for your team to review.
Frequently asked questions
Can an Aadhaar number be validated offline?
Its structure can: twelve digits, a first digit of 2 to 9, and a passing Verhoeff check digit. Ownership needs an authentication path UIDAI allows.
What does the fourth character of a PAN mean?
The holder type. P is an individual, C a company, H a Hindu undivided family, F a firm, T a trust.
Can a business store Aadhaar numbers?
Only where the law allows it. Use masked Aadhaar, the signed QR or a reference number wherever you can.
What is an inoperative PAN?
A PAN not linked to Aadhaar by the deadline. From July 1, 2023 such PANs became inoperative until linked.
Does V-CIP allow fully automated onboarding?
No. RBI requires a live official in the V-CIP session. Automated liveness and face match support the official's decision.
API documentation
Read the endpoints, field names and webhook events in the docs, or book a call to scope India verification for your product.
Related pages