DigiLocker verification at hotel check-in: the guest journey, step by step
DigiLocker verification lets a hotel guest prove identity from their own phone using Aadhaar. It runs in one continuous flow, works whether or not the guest already has a DigiLocker account, and only needs to be set up once.

DigiLocker verification lets a hotel guest prove who they are at check-in without handing a photocopy across the desk. The guest accepts a consent notice on the property's check-in page, authenticates on a government domain, releases their Aadhaar and driving licence from DigiLocker, and comes back with a verified identity and a code for the front desk. It runs as one continuous flow on the guest's own phone. There is no app to download.
The flow takes one of two shapes depending on whether the guest already has a DigiLocker account. DigiGo works out which before the guest starts, so neither the guest nor the front desk ever has to ask. Both shapes end in the same place.
How does DigiLocker verification work at hotel check-in?
Before the DigiLocker link is generated, we check whether the guest's mobile number already has a DigiLocker account behind it. If it does, the guest is routed to sign in. If it does not, or the check is inconclusive, the guest is routed to sign up, and the account is created inline using Aadhaar.
Routing to sign up whenever the answer is unclear is deliberate. It is the path that works for everyone, including a guest whose DigiLocker account is registered to a number the property does not have on file.
If the guest already has a DigiLocker account
This is the common case and the shorter path. The guest accepts the consent notice, then signs in through Meri Pehchaan, the government's single sign-on service, using a mobile number, username or other ID. A one-time password goes to the registered mobile and email and stays valid for ten minutes. The guest enters their existing 6-digit DigiLocker PIN, chooses which issued documents to release, and DigiLocker fetches those documents from their issuers and returns a signed response. The guest lands back on the check-in page with KYC verified and a code for the desk.
If the guest has never used DigiLocker
Nothing about this case needs to reach the front desk. Where a returning guest signs in, a first-time guest enters an Aadhaar number instead, and DigiLocker creates the account and links the documents already issued against that Aadhaar. The guest sets a 6-digit PIN, which becomes their second factor from then on. From document consent onwards the path is identical to the returning guest's.
The account is created inside the check-in journey rather than in front of it. A guest who has never opened DigiLocker still finishes verification in the same session, on the same phone, without registering anywhere first.
Why does DigiLocker sometimes ask the guest to pick an account?
Because one mobile number can carry more than one DigiLocker account. This is common with family numbers, where a parent's number is registered against a spouse's or a child's account as well. When it happens, Meri Pehchaan interrupts sign in and asks the guest to choose.
The names on that screen are masked, which is the part that matters operationally. A guest tapping quickly can pick the wrong account, and the verification then returns a correct, government-signed identity belonging to the wrong person. Nothing in the response looks wrong, because nothing about it is malformed. The defence is to compare the returned name against the reservation, and that is a check the system should run rather than the front desk.
Staff should also recognise the screen when a guest flags it, because the instinct is to assume something has broken. Nothing has. The guest just needs to pick their own name.
Does the guest have to do this at every stay?
No. The account, the PIN and the linked documents are set up once and carry across stays. Every later check-in reuses the same DigiLocker account, so the guest moves straight from consent to sign in to document release. A guest who creates an account on this stay is a returning guest on the next one.
What should the front desk have in place?
- Keep manual document upload visible. A guest who stops partway through needs somewhere to go that is not the queue at the desk. The fallback should be on screen, not behind a support call.
- Automate the name match. The masked account picker is the one place where a technically successful verification can return the wrong guest. Comparing the returned name against the reservation closes it.
Where does the guest's data actually go?
The journey crosses four domains: the property's check-in page for the consent and the result, and accounts.digitallocker.gov.in, digilocker.meripehchaan.gov.in and consent.digilocker.gov.in for everything in between. The Aadhaar number, the one-time password and the security PIN are entered only on government domains. What comes back to the property is a signed response from the document issuer, showing each document against its issuing authority, the UIDAI for the e-Aadhaar and the transport department for the licence, plus a verification code for the desk.
That signed response is the whole point. It is the difference between collecting an ID and actually verifying one.




