Verify your identity
One time. Powered by DigiLocker (Govt. of India).
idpass will keep your name, address & masked Aadhaar last-4, encrypted on our server, to run the service. You control what portals see.
Three sides of the same login. Follow the person on their phone, the portal on the server, and a real website putting it together. Every screen below is illustrative.
Tip: the screen strips scroll sideways →
Your verified identity lives on your phone, locked in the hardware keystore and released only by your fingerprint. idpass never stores your Aadhaar number — only a masked last-4 you can choose to share.
One time. Powered by DigiLocker (Govt. of India).
idpass will keep your name, address & masked Aadhaar last-4, encrypted on our server, to run the service. You control what portals see.
Verified · device-bound ✓
Always shared:
Acme also requests (your choice):
Your data rights:
idpass is a standard OpenID Connect provider. If your stack already speaks OIDC, point it at our discovery URL and you’re done. Otherwise it’s a redirect, a token exchange, and a signed identity you verify against our JWKS.
Self-serve. No contract to start.
/idpass/signup and register your app.Copy these into your OIDC client config.
client_id = acme_9f3c... client_secret = •••••••••••• (keep server-side) redirect_uri = https://acme.example/callback scope = openid profile
Add your redirect URI(s) — where we send the user back after login.
Two lines, or your existing OIDC library.
<script src="https://atithipass.com/portal/sdk/idpass.js"></script> <button data-idpass>Login with idpass</button>
id_token is a signed JWS (RS256) — not encrypted.
There is no decryption step: you verify it against
https://atithipass.com/portal/oidc/jwks.json. Full copy-paste snippets (PHP/Node/Python) and a
Postman collection are in the developer docs.Base claims come with every login. Optional fields arrive only when you request the scope and the user toggles it on.
| Claim | Meaning | How to get it |
|---|---|---|
sub | Stable pseudonymous user ID (per your app) | always |
name | Verified full name | always profile |
dob_verified | Age/DOB confirmed against govt. source | always |
unique_id | Sybil-resistance hash — same human, one account (per app) | always |
loa / acr | Identity assurance level (2 = DigiLocker-proofed) | always |
device_bound | Login is tied to the user’s device key | always |
device_attested / attest_level | Whether the key is hardware-backed (TEE/StrongBox) — honest, never over-claimed | always |
amr | hwk (hardware key) or swk (software key) + mfa, user | always |
address | Verified postal address | on consent scope idpass:address |
aadhaar_last4 | Masked Aadhaar (last 4 digits only) | on consent scope idpass:aadhaar_last4 |
scope=openid profile idpass:address idpass:aadhaar_last4. If the user declines a
field, its claim is simply absent — build for that. A machine-readable
consent receipt records exactly what was shared, and is available to the user.
Stuck on POST /oidc/token? Ask us to enable the per-partner token-debug — see the
docs.This is exactly what a partner site does with the pieces above. You can run it live right now — no account needed.
A sample partner site. Sign in with your verified idpass identity — no password, no sign-up form.
🔐 Login with idpassOpen the idpass app and scan. On a phone the app opens directly.
Acme verified you via idpass — a KYC’d, device-bound human.
{
"name": "Ashish K.",
"dob_verified": true,
"loa": 2,
"device_bound": true,
"device_attested": false,
"amr": ["swk","mfa","user"],
"aadhaar_last4": "1234",
"unique_id": "b7f0…9a2",
"sub": "acme:af12…"
}
Download the app, enrol once, then log in anywhere. Manage sessions and your data from the wallet.
Create a partner account, grab your client_id, and follow the developer docs. Test against the live demo.