
Authentication
Authenticate every credential
Cryptographic proof that a document and its data are genuine, unaltered and issued by the authority that claims them.
Authentication, not inspection
Trust the maths, not the eye.
A trained officer can spot a poor forgery. A signature check catches every one. Authentication proves who issued a credential and that nothing in it has changed since in seconds, without judgement calls.
verified_user
Issued by the right authority
The data on the chip is signed by the issuing country or agency. Validating that signature against the trust list proves the credential came from a real issuer, not a convincing print shop.
memory
The original chip, not a copy
Active and chip authentication make the secure element prove it holds a private key that cannot be extracted — defeating a byte-perfect clone of the data.
lock
Unaltered since issue
Every data group has its own hash. Change a name, a date or a portrait and the check fails — so tampering is detected rather than argued about.
How a check runs
Six steps between the tap and the answer
Methods
Four ways to authenticate, layered to the risk
Not every service needs the full stack. A pharmacy counter and a border booth sit at different risk levels, the same platform supports both, and the programme decides how deep each check goes.
Chip / PKI authentication
Chip and PKI
Passive, active and chip authentication against the issuer’s certificates — the strongest proof, in under a second.

Optical features
UV, infrared and holographic features checked automatically by the reader, or by eye where no reader is available.
Signed QR code being scanned
Signed offline codes
Digitally signed QR and barcode credentials authenticate with no network and no call to the register.
Biometric authentication at point of service
Biometric binding
A 1:1 match ties the authenticated credential to the person presenting it, closing the borrowed-card gap.
Under the hood
Standards-based, and yours to operate.
public
ICAO and eMRTD
Full support for ICAO 9303 travel documents so credentials authenticate at any compliant border, not just at home.
account_tree
Certificate management
Trust lists, master lists and CRLs are distributed to every device and refreshed on schedule, so no reader authenticates on stale keys.
api
APIs and SDKs
Embed authentication into an existing app, kiosk or case-management system, including MOSIP-based platforms, without rewriting it.




