Developer reference
SSN verification API: number structure, invalid ranges and record checks
The United States has no national ID card. A bank's customer identification program collects four things: name, date of birth, address and an identification number, which for a US person is a taxpayer identification number, usually the Social Security Number. The SSN has nine digits in three groups, and since June 25, 2011 the Social Security Administration issues it at random. The deepidv verification API validates the number, authenticates the photo ID and matches the face to it in one session.
Last reviewed October 2026
Field layout of the 9-digit SSN
| Digits | Field | Implementation notes |
|---|---|---|
| 1-3 | Area number | Before June 25, 2011, tied to the state of the issuing office. Since then, random. |
| 4-5 | Group number | 00 is never issued. |
| 6-9 | Serial number | 0000 is never issued. |
Ranges that are never valid
- Area 000, area 666 and areas 900 to 999 are never issued as SSNs.
- Numbers starting with 9 belong to the IRS: an ITIN starts with 9 and has digits 4 and 5 in 50 to 65, 70 to 88, 90 to 92 or 94 to 99. Accept an ITIN as a TIN where your program allows, and label it as one.
- Group 00 and serial 0000 are never issued.
- 078-05-1120 was printed on a sample card in a wallet insert in 1938 and has been misused for decades. Block it.
- After randomization, the area number says nothing about where a person was born or lived. A parser that infers state from it is wrong for every number issued since 2011.
Response contents of an SSN verification API
A parse result tells you whether a number is well formed. A verification response tells you whether the person in front of the camera owns it. deepidv runs one session: document capture with OCR and the AI document fraud check, face liveness with a 1:1 match to the document photo, an SSN record check where your program is eligible, PEP and sanctions screening, and an optional 1:N match that flags the same face behind a second account.
- One decision per session, with an outcome for every step, delivered by webhook (session.status.verified, session.status.rejected, session.status.failed).
- A reason for every non-pass outcome, separating malformed input, a record that was not found, a mismatch between document and record, and a registry that did not answer.
- A signed verification receipt with a UTC timestamp per step, anchored on Base L2 with zero personal data on chain, checkable at proof.deepidv.com.
Capturing state IDs and passports
State driver's licences and ID cards follow the AAMVA card design standard, with a PDF417 barcode on the back encoding the printed data. deepidv reads front and back and flags a mismatch, a common sign of a tampered card. REAL ID compliant cards carry a star marking. US passports and passport cards are supported, with NFC chip reading for the passport book.
eCBSV and other record checks
The Social Security Administration's electronic Consent Based SSN Verification service (eCBSV) returns a match or no match on name, date of birth and SSN, plus a death indicator. It is open only to permitted entities, generally financial institutions under the Gramm-Leach-Bliley Act and their service providers, and only with the number holder's consent. Where eCBSV is out of reach, deepidv confirms the person through the document, the face, and phone signals such as carrier match, line type and SIM swap recency.
Liveness and remote CIP
The CIP rule is risk-based: it requires procedures that let a bank form a reasonable belief it knows the customer's true identity, using documentary methods, non-documentary methods or both. deepidv supplies both in one session: document authentication with a live face match, and non-documentary signals from phone and record checks. The receipt records which method confirmed which data point, which is what an examiner asks for.
How deepidv runs US verification
deepidv is a verification engine and agentic compliance suite built from the ground up, without third-party verification APIs underneath. The engine is SOC 2, ISO 27001 and PCI DSS certified, and deepidv is a member of DIACC and the AVPA. Luna, the verification agent, builds and sends United States verification workflows from the platform or from any LLM through MCP. Arbiter, the compliance agent, maps the workflow to FinCEN's CIP rule requirements, monitors accounts after onboarding and drafts suspicious transaction reports for FinCEN for your team to review.
Frequently asked questions
Can an SSN be validated offline?
Only its structure: nine digits, no area 000, 666 or 900 to 999, no group 00 and no serial 0000. Whether it belongs to the person needs a record check.
Does the area number still show the state of issue?
Not for numbers issued since June 25, 2011, when the SSA moved to random assignment.
Is an ITIN the same as an SSN?
No. An ITIN is issued by the IRS to people who need a TIN but cannot get an SSN. It starts with 9.
What does eCBSV return?
A match or no match on name, date of birth and SSN, and a death indicator. It does not return the person's details.
Must a bank collect an SSN from every customer?
From US persons it collects a TIN. For non-US persons the CIP rule allows other numbers, such as a passport number with the issuing country.
API documentation
Read the endpoints, field names and webhook events in the docs, or book a call to scope United States verification for your product.
Related pages