In brief: UIDAI is the statutory authority that issues Aadhaar and runs the systems used to authenticate Aadhaar holders, which is why it sits at the centre of Aadhaar-based KYC.
On this page
What UIDAI is
The Unique Identification Authority of India (UIDAI) is the statutory authority, under the Ministry of Electronics and Information Technology, responsible for issuing Aadhaar numbers and operating the authentication infrastructure that eKYC and identity-verification services rely on.

Why it matters for verification
Every Aadhaar-based verification API — whether it checks demographic details, runs OTP-based eKYC, or does an offline XML check — ultimately authenticates against UIDAI’s central system. UIDAI sets the rules for how that authentication can be used, including consent requirements and data-storage restrictions like the Aadhaar Vault mandate.

How UIDAI shapes Aadhaar-based verification
UIDAI decides how Aadhaar can be used for authentication and e-KYC, who can use which services, and what safeguards apply. Businesses that verify customers with Aadhaar operate within those rules, directly or through permitted partners and routes.
Ways Aadhaar is used in verification
- Authentication: confirming an Aadhaar holder’s identity, for example with an OTP sent to their registered mobile number.
- e-KYC: receiving the holder’s demographic details and photograph after authentication, where permitted.
- Offline verification: using UIDAI-signed documents or QR codes that the holder shares, without a live authentication call.
- DigiLocker: receiving Aadhaar-based details through the holder’s consented DigiLocker share.
Privacy features from UIDAI
UIDAI provides tools that help holders limit what they share, including the 16-digit virtual ID and masked Aadhaar, which hides most of the number. Supporting these in your flow reduces the sensitive data you handle.
Handling Aadhaar data responsibly
Collect Aadhaar data only where the rules permit, mask the number wherever it is displayed or stored, restrict access, and keep consent records. The authoritative guidance is on the UIDAI website.
What this means for businesses that verify Aadhaar
Any business that uses Aadhaar in onboarding works inside rules it does not set. Only entities authorised under the Aadhaar Act can perform online authentication, and they must follow the security, consent and data-storage requirements attached to that authorisation. Everyone else can still accept Aadhaar in offline forms, such as the signed offline XML or the Secure QR code, which can be checked without calling the central system.
In practice, that means asking for clear consent, collecting only what the process needs, masking the number wherever it is shown or stored, and keeping a record of what was checked and when. These habits also make it easier to switch between offline and online methods as your product grows, without rebuilding how you store identity data.
It also helps to keep up with official notices. Rules about which forms of Aadhaar can be accepted, how numbers must be masked and how virtual IDs work have changed over the years, and the authority publishes those changes on its own website. Checking those notices before you change your onboarding flow is cheaper than reworking it after an audit.
Businesses that follow those notices also find it easier to explain their process to auditors, because each step can be traced back to a published rule.
Keeping that link between rule and process also makes training new staff much simpler.
A short internal summary of the current rules, reviewed each quarter, keeps every team working from the same understanding.
When rules change, update that summary first, then the processes and forms that depend on it, so nothing is missed.

Related terms
