How idpass works — end to end

Three sides of the same login. Follow the person on their phone, the portal on the server, and a real website putting it together. Every screen below is illustrative.

Tip: the screen strips scroll sideways →

① For people · the idpass app

Enrol once, then log in with a tap

Your verified identity lives on your phone, locked in the hardware keystore and released only by your fingerprint. idpass never stores your Aadhaar number — only a masked last-4 you can choose to share.

🔐 idpass · Enrol
Verify your identity

One time. Powered by DigiLocker (Govt. of India).

🪪 DigiLocker e-KYC
🙂 Quick face match

idpass will keep your name, address & masked Aadhaar last-4, encrypted on our server, to run the service. You control what portals see.

Continue with DigiLocker
1Enrol. Verify with DigiLocker + a face check. A device-bound key is created in secure hardware.
🔐 idpass · Wallet
👤
Ashish K.

Verified · device-bound ✓

✅ Identity verified (LoA 2)
🔑 Hardware-backed key
🛡️ Aadhaar never stored (last-4 only)
Scan QR to log in
2Your wallet. One verified identity, ready to use anywhere. Nothing to remember, no password.
🔐 idpass · Approve login
Acme Portal wants to sign you in

Always shared:

NameAshish K.
✅
Verified age/DOB18+ confirmed
✅

Acme also requests (your choice):

Addressidpass:address
Aadhaar last-4idpass:aadhaar_last4
👆 Approve with fingerprint
3You decide. Optional fields default off. Your fingerprint signs the exact set you allow — a portal can’t get more.
🔐 idpass · Sessions
Where you’re signed in
Acme PortalToday · address off, last-4 on
Logout
XSInfosol KYC2 days ago
Logout

Your data rights:

⬇ Export my data
🗑 Delete my identity
4Stay in control. See every session, view your consent receipts, export or erase everything (DPDP).
🔒 Why it’s safe: the login capability is a key that lives in your phone’s Trusted Execution Environment and only signs after a biometric unlock. Losing your password is impossible — there isn’t one. A phishing site can’t replay your approval because each one is bound to that specific portal and request.
② For portals · the server side

Add “Login with idpass” to your product

idpass is a standard OpenID Connect provider. If your stack already speaks OIDC, point it at our discovery URL and you’re done. Otherwise it’s a redirect, a token exchange, and a signed identity you verify against our JWKS.

https://atithipass.com/portal/idpass/signup

Create your partner account

Self-serve. No contract to start.

OrganisationAcme Pvt Ltd
App nameAcme Portal
Create app →
1Sign up at /idpass/signup and register your app.
https://atithipass.com/portal/partners

Your credentials

Copy these into your OIDC client config.

client_id     = acme_9f3c...
client_secret = ••••••••••••  (keep server-side)
redirect_uri  = https://acme.example/callback
scope         = openid profile

Add your redirect URI(s) — where we send the user back after login.

2Get client_id + secret and register your redirect URI in the console.
acme.example/login

Drop in the button

Two lines, or your existing OIDC library.

<script src="https://atithipass.com/portal/sdk/idpass.js"></script>
<button data-idpass>Login with idpass</button>
🔐 Login with idpass
3Add the button. Use our tiny JS snippet or any standard OIDC client (Passport, Spring, etc.).

What happens under the hood

1 · Authorize
Redirect the user to idpass with PKCE.
GET /oidc/authorize?client_id=…&code_challenge=…
2 · Approve
Desktop shows a QR; the user approves in the app with a fingerprint.
QR ↔ idpass app · biometric
3 · Token
Exchange the code (+ verifier) for tokens.
POST /oidc/token → id_token, access_token
4 · Verify
Verify the id_token signature against our JWKS.
GET /oidc/jwks.json (RS256)
The id_token is a signed JWS (RS256) — not encrypted. There is no decryption step: you verify it against https://atithipass.com/portal/oidc/jwks.json. Full copy-paste snippets (PHP/Node/Python) and a Postman collection are in the developer docs.

What you receive

Base claims come with every login. Optional fields arrive only when you request the scope and the user toggles it on.

ClaimMeaningHow to get it
subStable pseudonymous user ID (per your app)always
nameVerified full namealways profile
dob_verifiedAge/DOB confirmed against govt. sourcealways
unique_idSybil-resistance hash — same human, one account (per app)always
loa / acrIdentity assurance level (2 = DigiLocker-proofed)always
device_boundLogin is tied to the user’s device keyalways
device_attested / attest_levelWhether the key is hardware-backed (TEE/StrongBox) — honest, never over-claimedalways
amrhwk (hardware key) or swk (software key) + mfa, useralways
addressVerified postal addresson consent scope idpass:address
aadhaar_last4Masked Aadhaar (last 4 digits only)on consent scope idpass:aadhaar_last4
To request extra fields, add their scopes to your authorize call: scope=openid profile idpass:address idpass:aadhaar_last4. If the user declines a field, its claim is simply absent — build for that. A machine-readable consent receipt records exactly what was shared, and is available to the user. Stuck on POST /oidc/token? Ask us to enable the per-partner token-debug — see the docs.
③ The website · putting it together

See it on a real site — “Acme Portal”

This is exactly what a partner site does with the pieces above. You can run it live right now — no account needed.

https://atithipass.com/portal/demo

Acme Portal

A sample partner site. Sign in with your verified idpass identity — no password, no sign-up form.

🔐 Login with idpass
1Visit the site and click Login with idpass.
https://atithipass.com/portal/oidc/authorize?client_id=…

Scan to sign in

Open the idpass app and scan. On a phone the app opens directly.

2Scan the QR with your idpass app and approve with a fingerprint (Part ①).
acme.example/callback?code=…&state=…

✓ Signed in

Acme verified you via idpass — a KYC’d, device-bound human.

{
  "name": "Ashish K.",
  "dob_verified": true,
  "loa": 2,
  "device_bound": true,
  "device_attested": false,
  "amr": ["swk","mfa","user"],
  "aadhaar_last4": "1234",
  "unique_id": "b7f0…9a2",
  "sub": "acme:af12…"
}
3You’re in. The site receives a verified, device-bound identity — plus only the extras you consented to.
▶ Run the live demo Get the app first

👤 I’m a user

Download the app, enrol once, then log in anywhere. Manage sessions and your data from the wallet.

🏢 I’m a portal

Create a partner account, grab your client_id, and follow the developer docs. Test against the live demo.