Integration Guides

DigiLocker API Integration for KYC: Process and Pricing

How DigiLocker integration works for KYC: becoming a requester, the consent flow, which documents you can pull, legal validity, direct versus aggregator access and cost.

Purushottam Kumar Suman
Purushottam Kumar Suman
Founder & CEO, Drema AI
7 min read
Documents arranged on a desk

DigiLocker lets a person share government-issued documents directly from the issuer's database, with consent, in a few taps. For KYC this is better than a photographed card: the data comes from the source, is digitally signed and cannot be edited by the user.

01

Issuers and requesters

DigiLocker has two kinds of partners. Issuers, such as UIDAI, the Income Tax Department, transport departments and education boards, publish documents into it. Requesters are organisations that ask users to share documents. For KYC you integrate as a requester.

Aadhaare-Aadhaar data with name, date of birth, gender, address and photograph; the Aadhaar number is masked
PANPAN verification record
Driving licence and vehicle registrationFrom the transport databases
Education certificatesMark sheets and certificates from participating boards and universities
OthersInsurance policies, ration cards and many state-issued documents
02

How the flow works

The integration follows the OAuth 2.0 authorisation code pattern.

Always exchange the code and fetch documents from your server. The client secret never belongs in a mobile app.

1. RedirectYour app sends the user to DigiLocker with your client ID and requested scope
2. Sign in and consentThe user signs in with mobile or Aadhaar and OTP, and approves sharing
3. Authorisation codeDigiLocker redirects back to your registered callback with a code
4. TokenYour server exchanges the code for an access token
5. FetchCall the APIs to list issued documents and pull files or structured XML
6. Verify and storeValidate the digital signature, extract fields and store according to your retention rules
03

Legal standing

Under the Information Technology rules governing digital locker facilities, documents issued through DigiLocker are to be treated on par with original physical documents. RBI's KYC rules recognise documents obtained through DigiLocker as a form of officially valid document, and SEBI and IRDAI accept them for onboarding in their sectors. Confirm the specific wording for your regulator and product.

04

Direct access or an aggregator

There are two ways to integrate.

Direct as a requesterApply through the DigiLocker partner portal on API Setu, with organisation documents and use case. Approval takes time and you maintain the integration
Through an aggregatorKYC API providers that are already onboarded expose DigiLocker as one API with a hosted flow. Faster to launch, with a per-verification fee
05

Pricing

The cost most businesses see is the aggregator's fee, typically a few rupees per successful document pull, falling with volume and often bundled with PAN, bank account and face match checks. Direct requester access is governed by the DigiLocker partner terms in force at the time you apply; check the partner portal for current charges, as terms have changed over time. Include the cost of failed and abandoned sessions when comparing providers.

Per pull
How aggregators usually charge
Signed
Documents carry the issuer's digital signature
Masked
Aadhaar number is not shared in full
06

Design and compliance tips

Not every user has a DigiLocker account or a mobile number linked to Aadhaar, so keep a fallback such as offline Aadhaar verification or document upload with video KYC. Ask only for the documents you need. Store the signed XML as evidence, restrict access, and apply retention rules under the DPDP Act and your sector regulator.

Fallback KYC pathMinimal scopeSignature validationName match logicConsent recordEncrypted storageRetention policy
Sources · last reviewed October 1, 2026

This article explains what to build, not legal advice. Rules change; confirm against the current official text before relying on it.

Purushottam Kumar Suman
Written by
Purushottam Kumar Suman
Founder & CEO, Drema AI

Founder and CEO of Drema AI. Builds AI systems, SaaS platforms and industry software — and writes about what actually survives production.

CTA Background

Got a problem like this one?

Bring it to a call with a founder.You will get a straight answer, including when the answer is no.

View Our Work
AI-First Engineering
Secure & Scalable
Built to Deliver Impact