UIDAI (Unique Identification Authority of India)

In brief: UIDAI is the statutory authority that issues Aadhaar and runs the systems used to authenticate Aadhaar holders, which is why it sits at the centre of Aadhaar-based KYC.

What UIDAI is

The Unique Identification Authority of India (UIDAI) is the statutory authority, under the Ministry of Electronics and Information Technology, responsible for issuing Aadhaar numbers and operating the authentication infrastructure that eKYC and identity-verification services rely on.

UIDAI: a government building issuing identity cards to a line of people

Why it matters for verification

Every Aadhaar-based verification API — whether it checks demographic details, runs OTP-based eKYC, or does an offline XML check — ultimately authenticates against UIDAI’s central system. UIDAI sets the rules for how that authentication can be used, including consent requirements and data-storage restrictions like the Aadhaar Vault mandate.

UIDAI: a government building issuing identity cards to a line of people

How UIDAI shapes Aadhaar-based verification

UIDAI decides how Aadhaar can be used for authentication and e-KYC, who can use which services, and what safeguards apply. Businesses that verify customers with Aadhaar operate within those rules, directly or through permitted partners and routes.

Ways Aadhaar is used in verification

Privacy features from UIDAI

UIDAI provides tools that help holders limit what they share, including the 16-digit virtual ID and masked Aadhaar, which hides most of the number. Supporting these in your flow reduces the sensitive data you handle.

Handling Aadhaar data responsibly

Collect Aadhaar data only where the rules permit, mask the number wherever it is displayed or stored, restrict access, and keep consent records. The authoritative guidance is on the UIDAI website.

What this means for businesses that verify Aadhaar

Any business that uses Aadhaar in onboarding works inside rules it does not set. Only entities authorised under the Aadhaar Act can perform online authentication, and they must follow the security, consent and data-storage requirements attached to that authorisation. Everyone else can still accept Aadhaar in offline forms, such as the signed offline XML or the Secure QR code, which can be checked without calling the central system.

In practice, that means asking for clear consent, collecting only what the process needs, masking the number wherever it is shown or stored, and keeping a record of what was checked and when. These habits also make it easier to switch between offline and online methods as your product grows, without rebuilding how you store identity data.

It also helps to keep up with official notices. Rules about which forms of Aadhaar can be accepted, how numbers must be masked and how virtual IDs work have changed over the years, and the authority publishes those changes on its own website. Checking those notices before you change your onboarding flow is cheaper than reworking it after an audit.

Businesses that follow those notices also find it easier to explain their process to auditors, because each step can be traced back to a published rule.

Keeping that link between rule and process also makes training new staff much simpler.

A short internal summary of the current rules, reviewed each quarter, keeps every team working from the same understanding.

When rules change, update that summary first, then the processes and forms that depend on it, so nothing is missed.

UIDAI: a secure data centre with an identity card and a lock
UIDAI: a secure data centre with an identity card and a lock

Verify it with Veriqos Technologies

← Back to the verification glossary