Skip to main content
POST
DigiLocker initiate
Starts a DigiLocker-based Aadhaar verification. Returns the DigiLocker authorization link and an access_request_id. Redirect the customer to the link to complete OAuth on the DigiLocker portal, then finalize with DigiLocker Verify.
Authenticate with your parent main account’s X-Auth-ID and X-Auth-Token - the same credentials used everywhere else in the API.
1

Initiate

Call this endpoint with your redirect_url (and optional oauth_state). Capture access_request_id and send the customer to the returned auth_url.
2

Customer completes OAuth

The customer authorizes on the DigiLocker portal and is returned to your redirect_url.
3

Verify

Call DigiLocker Verify with the access_request_id.

Request body

Response example

200 OK
Store the access_request_id against the customer’s session before redirecting. The OAuth round-trip happens in the customer’s browser; you finalize server-side in the next step using this id.

Authorizations

X-Auth-ID
string
header
required

Your Vobiz account Auth ID

X-Auth-Token
string
header
required

Your Vobiz account Auth Token

Path Parameters

sub_auth_id
string
required

The sub-account's Auth ID.

Example:

"SA_XXXXXX"

Body

application/json
redirect_url
string<uri>
required
Example:

"https://partner.example.com/kyc/callback"

oauth_state
string

Opaque value echoed back on the redirect for CSRF protection.

Example:

"opaque-state-xyz"

Response

200 - application/json

DigiLocker authorization link