deepidv Logo

Developer reference

India Aadhaar and PAN verification API: number structure, Verhoeff check and KYC rules

India's two KYC identifiers work differently. Aadhaar is a twelve-digit number from UIDAI whose last digit is a Verhoeff check digit. PAN is a ten-character code from the Income Tax Department whose fourth character tells you what kind of holder it belongs to. Both can be validated offline for structure, and both have strict rules on how they are verified and stored. The deepidv verification API validates both, reads the signed Aadhaar QR and matches the face live.

Last reviewed October 2026

Structure of Aadhaar and PAN

Aadhaar number fields by position
DigitsFieldImplementation notes
1First digitNever 0 or 1, so a valid number begins 2 to 9.
2-11Random digitsNo date, region or gender.
12Check digitVerhoeff algorithm, which catches all single-digit errors and adjacent transpositions.
PAN fields by position
CharactersFieldImplementation notes
1-3Alphabetic seriesAAA to ZZZ.
4Holder typeSee the code list below.
5Name initialFirst letter of the surname for individuals, of the name for other holders.
6-9Sequential numberFour digits.
10Check characterAlphabetic.

PAN holder-type codes

  • P Individual
  • C Company
  • H Hindu undivided family
  • F Firm or LLP
  • A Association of persons
  • B Body of individuals
  • T Trust
  • L Local authority
  • J Artificial juridical person
  • G Government

A retail onboarding flow that accepts a PAN whose fourth character is not P is onboarding a business as a person.

Response contents of an India verification API

A parse result tells you whether a number is well formed. A verification response tells you whether the person in front of the camera owns it. deepidv runs one session: document capture with OCR and the AI document fraud check, face liveness with a 1:1 match to the document photo, PAN verification and the Aadhaar check your licence allows, PEP and sanctions screening, and an optional 1:N match that flags the same face behind a second account.

  • One decision per session, with an outcome for every step, delivered by webhook (session.status.verified, session.status.rejected, session.status.failed).
  • Fields as printed on the document, with a normalized Latin form in its own field where the document uses another script.
  • A reason for every non-pass outcome, separating malformed input, a record that was not found, a mismatch between document and record, and a registry that did not answer.
  • A signed verification receipt with a UTC timestamp per step, anchored on Base L2 with zero personal data on chain, checkable at proof.deepidv.com.

Capturing Aadhaar, the secure QR and PAN

The Aadhaar letter, card and e-Aadhaar carry a secure QR code signed by UIDAI. deepidv verifies the signature offline, which proves the data came from UIDAI without an online call. Fields appear in English and a regional script; deepidv returns both, with the Latin form in its own field. Use masked Aadhaar, where the first eight digits are hidden, whenever you do not need the full number.

Aadhaar and PAN record checks

Online Aadhaar authentication and e-KYC are open only to entities licensed by UIDAI, or through one. Offline paths, such as the signed QR, the Aadhaar paperless offline e-KYC XML with a share code, and DigiLocker, work without that licence. PAN verification confirms the PAN is valid, the name on record, and whether it is operative: PANs not linked to Aadhaar became inoperative from July 1, 2023. deepidv runs the offline Aadhaar QR, the offline e-KYC XML, DigiLocker and PAN verification live, and confirms each path with you before enabling it.

Liveness, V-CIP and RBI rules

RBI's Master Direction on KYC allows Video based Customer Identification Process (V-CIP) for remote onboarding, run live by an official of the regulated entity with liveness checks, geotagging and recording. deepidv supplies the liveness result, face match and document checks the official relies on, and records every step with a timestamp. Personal data handling falls under the Digital Personal Data Protection Act 2023.

How deepidv runs India verification

deepidv is a verification engine and agentic compliance suite built from the ground up, without third-party verification APIs underneath. The engine is SOC 2, ISO 27001 and PCI DSS certified, and deepidv is a member of DIACC and the AVPA. Luna, the verification agent, builds and sends India verification workflows from the platform or from any LLM through MCP. Arbiter, the compliance agent, maps the workflow to RBI's Master Direction on KYC requirements, monitors accounts after onboarding and drafts suspicious transaction reports for FIU-IND for your team to review.

Frequently asked questions

Can an Aadhaar number be validated offline?

Its structure can: twelve digits, a first digit of 2 to 9, and a passing Verhoeff check digit. Ownership needs an authentication path UIDAI allows.

What does the fourth character of a PAN mean?

The holder type. P is an individual, C a company, H a Hindu undivided family, F a firm, T a trust.

Can a business store Aadhaar numbers?

Only where the law allows it. Use masked Aadhaar, the signed QR or a reference number wherever you can.

What is an inoperative PAN?

A PAN not linked to Aadhaar by the deadline. From July 1, 2023 such PANs became inoperative until linked.

Does V-CIP allow fully automated onboarding?

No. RBI requires a live official in the V-CIP session. Automated liveness and face match support the official's decision.

API documentation

Read the endpoints, field names and webhook events in the docs, or book a call to scope India verification for your product.

Related pages