DigiLocker API for Consent-Based KYC & Document Verification
Fetch and verify user-consented digital documents such as Aadhaar, PAN, driving licence, and other DigiLocker-issued records through secure, paperless API workflows for onboarding, lending, and compliance.
Starts at ₹2.50 per request · excl. GSTView Pricing
Overview
The DigiLocker API enables businesses to fetch and verify user documents digitally with explicit consent. It eliminates manual document collection, reduces fraud, and accelerates onboarding through trusted digital records.
What Can You Verify With DigiLocker Integration APIs?
Key details returned across all DigiLocker API endpoints, ready to power your KYC and onboarding workflows.
DigiLocker URL
DigiLocker redirect URL. Present this URL to the customer to begin document authorisation.
Document Type
Type of document retrieved (e.g. AADHAAR).
Name
Full name as per the verified document.
Date of Birth
Date of birth from the verified document.
Gender
Gender as per document: M, F, or T.
Masked Aadhaar
Aadhaar number with first 8 digits masked.
Address
Residential address from the verified Aadhaar.
House
House or flat number.
Street
Street or locality name.
Village Or City
Village or city.
District
District.
State
State.
Pincode
6-digit postal code.
Photo
Base64-encoded photograph from the Aadhaar document.
Verification Status
Overall DigiLocker verification status: SUCCESS or PENDING.
DigiLocker API Flow – Sample Request and Response
Send simple inputs. Get rich, verified data in seconds.
Generate a DigiLocker redirect URL to initiate consent-based Aadhaar document retrieval.
Key Features
Everything you need to integrate and scale
Consent-Based Document Access
Fetch documents only after explicit user consent, ensuring transparency and trust.
Digital Document Retrieval
Access verified digital documents without physical copies.
Automation Ready
Integrates seamlessly into digital onboarding and compliance systems.
Scalable Architecture
Designed to handle high-volume document access reliably.
Who Should Use This API?
Primary Use Cases
How to Integrate
Get started in minutes with our simple integration process
- 1
Sign Up
Sign up in minutes with your mobile number (OTP verify).
- 2
Verify Identity
Complete your basic KYC with PAN and address details to verify your identity.
- 3
Test APIs Live
Load funds into your wallet and test the verification APIs live — evaluate before you integrate.
- 4
Integrate with AI
Ready to build? Visit our AI hub for free plugins & tools to integrate faster.
- 5
Go Live
Start accessing digital documents in production.
Frequently Asked Questions
Does the DigiLocker API use OTP or redirect-based consent?+
The DigiLocker API uses a redirect-based consent mechanism. The user may authenticate through DigiLocker using the supported login or OTP process and then approve document sharing. Your application receives the verification result through the configured callback or API response.
Is DigiLocker access consent-based?+
Yes, documents are fetched only after explicit user consent, ensuring full transparency.
What documents can be accessed?+
You can access government-issued digital documents like Aadhaar, PAN, driving license, and more through DigiLocker.
Does it eliminate physical document collection?+
Yes, the API enables fully paperless document verification, eliminating manual collection.
How do I get started?+
Four steps: sign up at the developer console page, verify your identity with PAN and address details, load your wallet to test the APIs live, then integrate and go live. Sandbox credentials are issued immediately — you can call your first endpoint before any paperwork clears.
What is EPS?+
EPS (Eko Platform Services) is the technology arm of Eko — the developer tools, AI tooling and APIs that power modern fintech integration, from money transfer and AePS to identity verification.
What are the different ways to integrate with Eko EPS?+
Three paths, pick whichever suits your stack:
- Call the REST APIs directly.
- Use our official Node.js, Python, PHP, Go or Java SDKs to skip request-signing boilerplate.
- Let an AI coding agent build it via our MCP server and agent skills.
For multi-step flows (onboard a sender, then transfer) start from a transaction-flow recipe rather than wiring single endpoints together yourself.
How does API authentication work?+
Each request carries your static developer_key header plus a per-request secret-key header — an HMAC-SHA256 signature of the current timestamp, keyed by your access key. The access key itself is never sent over the wire. You receive UAT keys on signup and production keys after KYC.
The How Authentication Works guide has the full signing recipe in five languages plus an in-browser playground that generates and verifies a real secret-key against your own access key.
Is there a sandbox environment for testing?+
Yes. A full sandbox is available immediately on signup — test your integration end-to-end before going live, no commitment required. For offline work you can also run our mock server (npx -y @ekoindia/eps-mock-server) and get canned responses with no network calls at all.
What are the sandbox and production base URLs?+
Sandbox and production share the same paths and differ only by base URL:
- UAT / Sandbox —
https://staging.eko.in/ekoapi/v3 - Production —
https://api.eko.in/ekoicici/v3
A common cause of failures is calling the sandbox URL with live credentials, or vice-versa — make sure the base URL matches the keys you are using.
Do I need to whitelist my server IP?+
Production API access may require your static public (server) IP to be whitelisted. If your calls work from Postman but fail or time out from your own server, that is almost always the cause — share your static public IP with us so we can whitelist it.
Can an AI coding agent build the integration for me?+
Yes — that is the fastest path. Point your agent (Claude Code, Codex, Cursor, Copilot, …) at our MCP server and it can look up any endpoint, generate correctly-signed requests, and scaffold the integration in your own stack. Install it in one step from the AI hub, or start from a ready-made prompt.
We also publish an OpenAPI 3.1 spec, a Postman collection and per-agent context packs (AGENTS.md, CLAUDE.md, .cursorrules) so an agent has the ground truth instead of guessing.
What response times can I expect?+
Most verification APIs return in real time with sub-second responses, and 99th-percentile latency stays under two seconds across verification endpoints. Transaction APIs (DMT, AePS, BBPS) respond within seconds.
Can the API handle high volumes?+
Yes. The API is designed to handle large-scale volumes reliably without performance degradation.
How is API usage billed?+
Usage is billed per successful API call with no minimum commitment. Volume-based pricing tiers are available — see the pricing calculator for indicative rates, or contact our team for a custom quote.
Recommended Solution Packs
Pre-bundled API stacks that include DigiLocker API, designed for common industry workflows.
Get API Access
Sign up now and start integrating in minutes. Our team will help you go live quickly.
- Sandbox access in minutes
- Dedicated integration support
- Comprehensive documentation
- Reliable, high-volume workflows
Get DigiLocker API Access
Get started in 10 minutes