Aadhaar-Anchored DID in India

How AssureLocker bridges India's Aadhaar identity infrastructure with W3C Decentralised Identifiers (DIDs) — the cryptographic foundation for DigiKYC.

TechnicalAssureLocker Team·10 min read
Published: 12 March 2026Last updated: 26 May 2026Sources reviewed as of: 26 May 2026

Bridging IndiaStack with W3C Standards

India possesses the world's largest digital identity project: Aadhaar. However, Aadhaar was designed as a central database verification system. To enable a truly portable, privacy-preserving identity ecosystem, we need to bridge this central root of trust with decentralised standards.

The bridge is the Decentralised Identifier (DID).

What is a DID?

A DID is a new type of identifier that enables verifiable, decentralised digital identity. Unlike a bank account number or an Aadhaar number, a DID is not issued by a central authority. It is generated by the user and anchored to an immutable registry.

A typical DID in the AssureLocker ecosystem looks like this: did:web:ind.id.assurelocker.com:holder:1a2b3c4d5e...

  • did: The URI scheme.
  • web: The DID Method — W3C did:web, resolvable over HTTPS with standard tooling (no proprietary resolver).
  • ind.id.assurelocker.com: The resolution host — the ind subdomain is the jurisdiction (ISO 3166-1 alpha-3), served from that region.
  • holder: The actor type (holder, issuer, or verifier).
  • 1a2b3c...: The unique identifier string.

The Anchoring Process

AssureLockeruses Aadhaar as the "source of truth" to bootstrap a DID. Here is how the anchoring works:

  1. Authentication: The user authenticates via Aadhaar OTP (eKYC).
  2. Key Generation: A unique cryptographic key pair is generated on the user's device (often secured by FIDO2/Passkeys).
  3. DID Creation: AssureLockercreates a DID Document that links the user's public key to a unique DID.
  4. Registry Anchoring: The DID (or a hash of the DID Document) is recorded in an immutable registry, making it immutable and globally resolvable.

Crucial Detail:The Aadhaar number is never stored in the registry. The registry only contains the DID and the public key. The link between the Aadhaar identity and the DID is a "Verifiable Credential" held privately by the user.

Aadhaar bootstraps an anchored DID and a holder-controlled Verifiable Credential; a verifier checks the credential against the registry without ever seeing the Aadhaar numberA left-to-right chain: Aadhaar (UIDAI eKYC, used once) anchors a did:web identifier plus public key into an immutable registry; the issuer signs a Verifiable Credential the holder stores on device; the holder presents a signed proof to a verifier, which resolves the DID and public key from the registry to check the signature. A privacy boundary marks that the Aadhaar number never travels past the initial bootstrap.Aadhaar number stays left of hereSTEP 1AadhaarUIDAI eKYC · used onceSTEP 2Anchored DIDdid:web + public keySTEP 3Credential (VC)held on deviceSTEP 4Verifierchecks the proofanchorsissuespresentsIMMUTABLE REGISTRY / LEDGERstores the DID and a document hash only — no Aadhaar number, no PIIwrites DID + keyresolves + verifies
Aadhaar is used once to bootstrap the DID; from then on only the DID, the holder’s credential and a signed proof move. The verifier checks that proof against the registry — it never sees, and never needs, the Aadhaar number.

Why Aadhaar-Anchored DIDs?

Using DIDs instead of raw identifiers solves three critical problems:

1. Portability

Once a DID is established and anchored, the user can use it to interact with any service provider in the AssureLocker network without ever needing to perform a full Aadhaar eKYC again.

2. Privacy-Preserving Verification

Because the verifier checks the DID in the registry, they don't need to ping a central government database for every transaction. This reduces the footprint of the user across the internet.

3. Key Management

By anchoring the DID to a public key, we enable passwordless authentication. A user “proves” their identity by signing a challenge with their private key, which the verifier validates against the public key linked to the DID in the registry.

The Future of Identity in India

Aadhaar-anchored DIDs represent the next evolution of IndiaStack. By moving from "Identity as a Database Check" to "Identity as a Cryptographic Proof," we enable a more secure, faster, and more private financial ecosystem for everyone.


Primary sources

Continue reading

See AssureLocker in action

Book a 30-minute live walkthrough tailored to your lending use case.

Book a demo →
AssureLocker
AssureLocker Pvt Ltd. (inc. in progress)
3rd floor, Innov8, SKCL Tech Square, SIDCO Industrial Estate, Guindy,
Chennai, Tamil Nadu 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. AssureLocker Pvt Ltd. (inc. in progress), the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 AssureLocker Pvt Ltd.. All rights reserved. · Site version: al-20260905-192031-5156ce245