Authentication

Authenticate every credential

Cryptographic proof that a document and its data are genuine, unaltered and issued by the authority that claims them.

Authentication, not inspection

Trust the maths, not the eye.

A trained officer can spot a poor forgery. A signature check catches every one. Authentication proves who issued a credential and that nothing in it has changed since in seconds, without judgement calls.

verified_user

Issued by the right authority

The data on the chip is signed by the issuing country or agency. Validating that signature against the trust list proves the credential came from a real issuer, not a convincing print shop.

memory

The original chip, not a copy

Active and chip authentication make the secure element prove it holds a private key that cannot be extracted — defeating a byte-perfect clone of the data.

lock

Unaltered since issue

Every data group has its own hash. Change a name, a date or a portrait and the check fails — so tampering is detected rather than argued about.

Open the chip without leaking it

The reader and the chip negotiate an encrypted session using the key material printed on the document, so the exchange cannot be skimmed and the chip only answers a holder who physically presents the credential.

Open the chip without leaking it

The reader and the chip negotiate an encrypted session using the key material printed on the document, so the exchange cannot be skimmed and the chip only answers a holder who physically presents the credential.

Open the chip without leaking it

The reader and the chip negotiate an encrypted session using the key material printed on the document, so the exchange cannot be skimmed and the chip only answers a holder who physically presents the credential.

Check who signed the data

The document signer certificate is validated up the chain to the country signing certificate on the trust list. If the issuer is not trusted or the certificate has been revoked, the check stops here.

Check who signed the data

The document signer certificate is validated up the chain to the country signing certificate on the trust list. If the issuer is not trusted or the certificate has been revoked, the check stops here.

Check who signed the data

The document signer certificate is validated up the chain to the country signing certificate on the trust list. If the issuer is not trusted or the certificate has been revoked, the check stops here.

Confirm nothing has changed

Each data group — portrait, biographic fields, fingerprints — is hashed and compared against the signed document security object. A single altered byte is localised and reported.

Confirm nothing has changed

Each data group — portrait, biographic fields, fingerprints — is hashed and compared against the signed document security object. A single altered byte is localised and reported.

Confirm nothing has changed

Each data group — portrait, biographic fields, fingerprints — is hashed and compared against the signed document security object. A single altered byte is localised and reported.

Prove the chip is the original

The chip signs a random challenge with a private key that cannot be read out. A cloned credential holding identical data cannot answer, which is what separates a copy from the genuine document.

Prove the chip is the original

The chip signs a random challenge with a private key that cannot be read out. A cloned credential holding identical data cannot answer, which is what separates a copy from the genuine document.

Prove the chip is the original

The chip signs a random challenge with a private key that cannot be read out. A cloned credential holding identical data cannot answer, which is what separates a copy from the genuine document.

Tie the credential to the person

Where the service requires it, a live biometric is matched 1:1 against the authenticated chip data — so an intact, genuine credential still cannot be used by someone else.

Tie the credential to the person

Where the service requires it, a live biometric is matched 1:1 against the authenticated chip data — so an intact, genuine credential still cannot be used by someone else.

Tie the credential to the person

Where the service requires it, a live biometric is matched 1:1 against the authenticated chip data — so an intact, genuine credential still cannot be used by someone else.

Release only what is needed

The service receives an authenticated result and the minimum attribute set its policy allows. The check, its outcome and the device that made it are logged for audit.

Release only what is needed

The service receives an authenticated result and the minimum attribute set its policy allows. The check, its outcome and the device that made it are logged for audit.

Release only what is needed

The service receives an authenticated result and the minimum attribute set its policy allows. The check, its outcome and the device that made it are logged for audit.

Methods

Four ways to authenticate, layered to the risk

Not every service needs the full stack. A pharmacy counter and a border booth sit at different risk levels, the same platform supports both, and the programme decides how deep each check goes.

Chip / PKI authentication

Chip and PKI

Passive, active and chip authentication against the issuer’s certificates — the strongest proof, in under a second.

Optical features

UV, infrared and holographic features checked automatically by the reader, or by eye where no reader is available.

Signed QR code being scanned

Signed offline codes

Digitally signed QR and barcode credentials authenticate with no network and no call to the register.

Biometric authentication at point of service

Biometric binding

A 1:1 match ties the authenticated credential to the person presenting it, closing the borrowed-card gap.

Under the hood

Standards-based, and yours to operate.

public

ICAO and eMRTD

Full support for ICAO 9303 travel documents so credentials authenticate at any compliant border, not just at home.

account_tree

Certificate management

Trust lists, master lists and CRLs are distributed to every device and refreshed on schedule, so no reader authenticates on stale keys.

api

APIs and SDKs

Embed authentication into an existing app, kiosk or case-management system, including MOSIP-based platforms, without rewriting it.

A hand holding a Laxton handheld with its document scanner module lit

SECURE DOCUMENT AUTHENTICATION

Three light sources. One verdict on authenticity.

Scan any passport or ID card and cross-reference it with a global database of IDs to ensure the document is authentic.

Passport data page under white light

White

Passport data page under ultraviolet light

Ultra Violet

Passport data page under infra-red light

Infra-red

A hand holding a Laxton handheld with its document scanner module lit

SECURE DOCUMENT AUTHENTICATION

Three light sources. One verdict on authenticity.

Scan any passport or ID card and cross-reference it with a global database of IDs to ensure the document is authentic.

Passport data page under white light

White

Passport data page under ultraviolet light

Ultra Violet

Passport data page under infra-red light

Infra-red

A hand holding a Laxton handheld with its document scanner module lit

SECURE DOCUMENT AUTHENTICATION

Three light sources. One verdict on authenticity.

Scan any passport or ID card and cross-reference it with a global database of IDs to ensure the document is authentic.

Passport data page under white light

White

Passport data page under ultraviolet light

Ultra Violet

Passport data page under infra-red light

Infra-red

Frequently Asked Questions

What is document authentication?

Document authentication confirms that an identity document is genuine, unaltered, and issued by the legitimate authority, by reading and validating the physical and electronic security features built into it.

How is this different from a visual document check?

A visual check relies on an officer’s judgement and can be defeated by good forgeries. Authentication validates security features, machine-readable zones, and chip data against the document specification and issuing certificates, detecting alterations a visual check would miss.

Can the device confirm the person is the rightful holder?

Yes. It captures the holder’s fingerprint or face and matches it against the data on the document, exposing genuine documents presented by the wrong person.

Which documents can be authenticated?

ID cards, passports, and travel documents that carry standard physical and electronic security features, including ICAO-compliant chip-enabled travel documents.

What is the difference between verification and authentication?

The two answer different questions. Verification confirms the person, matching someone against their identity record to establish they are who they claim to be. Authentication confirms the document, validating its security features and chip data to establish the credential itself is genuine. In the field, officers need both: a real document presented by its rightful holder.

What security features can the device check?

UV and infrared elements, holographic overlays, machine-readable zones, laser-engraved data, and, where present, the document’s electronic chip and its cryptographic keys.

Does authentication work without connectivity?

Yes. Security features and chip data are validated on-device with pre-loaded certificates and reference data, so checks work fully offline and results synchronise once a connection is restored.

Is every check recorded?

Yes. Each authentication is logged with the result, time, location, and officer, producing a tamper-evident audit trail that supports oversight, investigations, and reporting.

What is document authentication?

Document authentication confirms that an identity document is genuine, unaltered, and issued by the legitimate authority, by reading and validating the physical and electronic security features built into it.

What is the difference between verification and authentication?

The two answer different questions. Verification confirms the person, matching someone against their identity record to establish they are who they claim to be. Authentication confirms the document, validating its security features and chip data to establish the credential itself is genuine. In the field, officers need both: a real document presented by its rightful holder.

How is this different from a visual document check?

A visual check relies on an officer’s judgement and can be defeated by good forgeries. Authentication validates security features, machine-readable zones, and chip data against the document specification and issuing certificates, detecting alterations a visual check would miss.

What security features can the device check?

UV and infrared elements, holographic overlays, machine-readable zones, laser-engraved data, and, where present, the document’s electronic chip and its cryptographic keys.

Can the device confirm the person is the rightful holder?

Yes. It captures the holder’s fingerprint or face and matches it against the data on the document, exposing genuine documents presented by the wrong person.

Does authentication work without connectivity?

Yes. Security features and chip data are validated on-device with pre-loaded certificates and reference data, so checks work fully offline and results synchronise once a connection is restored.

Which documents can be authenticated?

ID cards, passports, and travel documents that carry standard physical and electronic security features, including ICAO-compliant chip-enabled travel documents.

Is every check recorded?

Yes. Each authentication is logged with the result, time, location, and officer, producing a tamper-evident audit trail that supports oversight, investigations, and reporting.

What is document authentication?

Document authentication confirms that an identity document is genuine, unaltered, and issued by the legitimate authority, by reading and validating the physical and electronic security features built into it.

How is this different from a visual document check?

A visual check relies on an officer’s judgement and can be defeated by good forgeries. Authentication validates security features, machine-readable zones, and chip data against the document specification and issuing certificates, detecting alterations a visual check would miss.

Can the device confirm the person is the rightful holder?

Yes. It captures the holder’s fingerprint or face and matches it against the data on the document, exposing genuine documents presented by the wrong person.

Which documents can be authenticated?

ID cards, passports, and travel documents that carry standard physical and electronic security features, including ICAO-compliant chip-enabled travel documents.

What is the difference between verification and authentication?

The two answer different questions. Verification confirms the person, matching someone against their identity record to establish they are who they claim to be. Authentication confirms the document, validating its security features and chip data to establish the credential itself is genuine. In the field, officers need both: a real document presented by its rightful holder.

What security features can the device check?

UV and infrared elements, holographic overlays, machine-readable zones, laser-engraved data, and, where present, the document’s electronic chip and its cryptographic keys.

Does authentication work without connectivity?

Yes. Security features and chip data are validated on-device with pre-loaded certificates and reference data, so checks work fully offline and results synchronise once a connection is restored.

Is every check recorded?

Yes. Each authentication is logged with the result, time, location, and officer, producing a tamper-evident audit trail that supports oversight, investigations, and reporting.