Banking & IDs

Aadhaar checksum is not KYC. Stop pasting twelve digits into random sites

A green tick on a website is a terrible reason to feel identified. Aadhaar’s last digit is a checksum from the Verhoeff algorithm. A pass means twelve digits are self-consistent. It does not mean UIDAI issued the number to you, that the number is active, that it matches a face, or that the site you used is allowed to see it. The checksum tool on this site only does the first job, in this tab, and still asks you to think twice before pasting a real Aadhaar on a shared laptop. Employers collecting Aadhaar in public Google Forms are doing compliance cosplay.

Source: UIDAI. Enrolment, authentication, eKYC, VID, and biometric lock live there and on myAadhaar — not on a “free Aadhaar validator” that ranked for the query. I am not UIDAI. I do not look numbers up. I do not want yours.

What a checksum is for

Check digits catch typos and many swapped digits. Banks, insurers, and HR tools use the same idea so a mistyped twelve-digit string fails before it hits a queue. That is a kindness. It is also how phishing pages look official: they run Verhoeff, show a green badge, and then store the number. A leaked Aadhaar that still checksums will pass every toy validator on the internet, including mine. Treat success as “self-consistent digits,” not “good human.” Failure usually means a typo, an OCR glitch, or eleven digits. It is not a legal finding that a card is fake.

The tool page already says this in the FAQ. This note is the habit around it. Use a local check when you are filling a form you already decided to fill and you want to know whether you transposed two digits. Do not use any website, including this one, as a substitute for UIDAI authentication. Do not paste a number into a tab to “see if it is real.” Real is an UIDAI process. Consistent is arithmetic.

Phishing is boring and it works

The usual bait is not a Hollywood clone of uidai.gov.in. It is a Google ad, a WhatsApp PDF, or an SMS that says update, lock, or “Aadhaar will be deactivated.” UIDAI has said, repeatedly, that they do not ask for your Aadhaar number plus OTP over random links. Bookmark the official portal. Do not click the first search ad. Do not share the OTP that is meant for authentication. Do not photograph both sides of the card “for verification” into a Telegram group that is hiring. Lock biometrics from myAadhaar if you are not about to authenticate. None of that requires panic. It requires the same boredom you already apply to bank OTPs.

Shared computers are a quieter leak. Browser password managers, shoulder surfing, screenshots, and “just check this number for me” on a teammate’s laptop. The checksum script here does not POST the digits to a server I operate. Your colleague still has a screen. View source if you want the Verhoeff tables; they are not a secret. The number still is.

VID exists so you do not have to share Aadhaar

A Virtual ID is a 16-digit temporary number you generate from myAadhaar and can regenerate. UIDAI designed it so agencies can authenticate without holding the twelve-digit Aadhaar. It is a different scheme. Do not force sixteen digits into a twelve-digit checksum box and call the red text a conspiracy. Do not treat VID as “Aadhaar but secret forever”; it is a rotating handle, useful when a form will accept it. If a vendor insists on the raw Aadhaar in a shared spreadsheet, that is a vendor problem, not a checksum-tool problem.

Masked displays — XXXX-XXXX-1234 — are not full numbers. mAadhaar QR payloads are not twelve digits either. Do not paste QR guts into strangers’ textareas. If you only need last-four for a support ticket, send last-four, not the rest “for completeness.”

Worked example: typo, nobody at UIDAI was contacted

You meant to type twelve digits onto a bank form. You typed eleven, or you swapped two in the middle. The local check fails. You fix the typo. That is the entire product. Open the checksum tool, use a number you already intended to submit on a form you trust, or use a dummy shape to see the UI — the placeholder style is 1234 5678 9012, which is a shape, not an invitation to hunt for a passing test vector. Clear the field when you are done. Hide digits if someone is standing behind you. Nobody at UIDAI was pinged. A pass on a number you found in a breach dump would have looked the same.

Worked example: the Google Form that is not KYC

A startup’s intern shares a Form titled “KYC — paste Aadhaar.” Fifty contractors comply. The sheet sits in a Drive folder with “anyone with the link.” A checksum column later turns green for every row because someone pasted Verhoeff into Apps Script. That green column is not eKYC. It is a shared database of twelve-digit identifiers plus names and phone numbers. UIDAI’s compliant path is authentication / eKYC through licensed entities, with purpose limitation and logs. If you are the intern: stop. If you are the contractor: send a masked copy or a VID if the law and the vendor actually require identity, and ask for a proper flow. If you are me: I will not host the form for you.

What this note adds that the tool does not

The tool is a Verhoeff box with a mask toggle and a trust rail. This note is when to use it (typo check on a number you were already typing) and when not to (curiosity, “is this leaked number valid,” phishing pages with nicer badges, HR theatre). KYC is a legal process. Checksum is arithmetic. VID is the official way to stop spraying the twelve digits. Official materials live on uidai.gov.in. I am practical about this because the failure mode is a spreadsheet, not a movie. Do not paste Aadhaar into random sites. Mine is less random than most and still not a vault.