KYC API Guide — Digital Identity Verification
How to build a modern KYC stack using APIs — from PAN and Aadhaar verification to face matching and Video KYC.
What Is KYC?
Know Your Customer (KYC) is the process of verifying the identity of clients before or during a business relationship. In India, KYC is mandated by the RBI for all regulated financial entities — banks, NBFCs, fintechs, insurers, and payment processors.
A KYC API replaces manual document collection and in-person verification with programmatic, real-time identity checks. It enables instant account opening, reduces onboarding drop-offs, and maintains a complete audit trail for regulators.
Modern KYC goes beyond document verification. It encompasses identity document validation, biometric matching, liveness detection, address verification, and ongoing monitoring. Each layer adds confidence that the person interacting with your platform is who they claim to be.
For fintechs, a robust KYC API is not just compliance infrastructure — it is a competitive advantage. Faster onboarding means higher conversion rates. Better verification means lower fraud losses.
PAN, Aadhaar & CKYC
PAN Verification — Validates PAN card format, issued status, and holder name against Income Tax records. Essential for financial services and tax compliance.
Aadhaar Verification — OTP-based or biometric-based Aadhaar verification via UIDAI. Confirms identity with government-backed authentication.
CKYC — Central KYC Registry check. If a customer has completed KYC with any CKYC-registered entity, their record can be retrieved — eliminating重复 verification.
DL & Passport — Driving licence and passport verification for address confirmation and secondary identity proof.
Voter ID — EPIC card verification for customers who may not have PAN or Aadhaar as primary documents.
GST Verification — Verify GSTIN for business KYC — confirm entity name, registration status, and address.
Document Verification & OCR
Document OCR (Optical Character Recognition) extracts text from uploaded identity documents — PAN cards, Aadhaar cards, driving licences, and passports. Modern OCR APIs achieve 99%+ accuracy on Indian documents with support for Devanagari and regional scripts.
Beyond text extraction, document verification APIs check for tampering, verify security features, match fonts against known templates, and confirm that the document image is authentic — not a photocopy or screenshot.
Face matching compares a selfie or live photo against the photograph on the identity document. Liveness detection ensures the selfie is taken by a real person present at the moment — not a printed photo, video replay, or deepfake.
Together, document OCR + face match + liveness detection form the trifecta of remote identity verification. This stack enables fully digital onboarding with confidence levels comparable to in-person verification.
Face Match & Liveness Detection
Face Match — 1:1 comparison between a live photo and the document photo. Returns a similarity score with configurable threshold.
Passive Liveness — Detects spoofing attempts without requiring the user to perform actions. Analyzes texture, depth, and reflection patterns.
Active Liveness — Prompts the user to blink, turn their head, or follow a dot pattern. Higher assurance but slight UX friction.
Deepfake Detection — ML models trained to detect AI-generated faces, video replays, and synthetic media attacks.
Age & Gender Check — Estimate age and gender from the live photo and cross-reference against document data for consistency.
Device Intelligence — Capture device fingerprint, IP geolocation, and session metadata to detect organised fraud patterns.
Video KYC Workflow
Video KYC enables remote, real-time identity verification — eliminating the need for physical document submission or in-person visits.
Building a KYC Flow with APIs
# Full KYC verification — PAN + Face Match + Liveness curl --request POST \ --url https://api.scofit.app/v1/kyc/verify \ --header 'Authorization: Bearer sk_live_...' \ --header 'Content-Type: application/json' \ --data '{ "customer_id": "cust_m1n2o3", "document_type": "PAN", "document_number": "ABCPD1234X", "name": "Arjun Kumar", "consent": "yes", "purpose": "customer_onboarding" }' # → Response { "status": "success", "verification_id": "vrf_7d8e9f", "pan_valid": true, "name_match_score": 0.97, "face_match_score": 0.94, "liveness_passed": true, "overall_status": "VERIFIED", "verified_at": "2025-12-15T11:05:00Z" }
Regulatory Considerations
RBI KYC Master Direction — All regulated entities must follow RBI's KYC norms. Digital KYC is permitted under the 2016 Master Direction with 2020 amendments.
Video KYC Guidelines — RBI permits V-KYC for fully digital onboarding. Your implementation must meet recording, storage, and audit requirements.
Data Localisation — Customer data must be stored in India. Ensure your KYC provider's infrastructure is compliant with data localisation requirements.
Consent Management — Explicit, informed consent is required for Aadhaar-based authentication. Consent must be purpose-specific and revocable.
Record Retention — KYC records must be maintained for at least 5 years after the business relationship ends. Plan storage accordingly.
Plot No. 260, Scheme No. 54, PU4, Behind Malhar Mall, Indore, Madhya Pradesh 452001