MOSIP

Digital Identity

MOSIP is an open-source platform countries use to build foundational national identity systems, covering enrolment, biometrics, ID issuance, authentication, eKYC and credential management. It is a reference example of identity DPI: API-first, modular, privacy-engineered, and deployed or being deployed in the Philippines, Morocco, Sri Lanka, Ethiopia, Guinea, Togo and elsewhere.

Biometric enrollment
eKYC
authentication
ID issuance
credential management
resident services

All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.

18 of 18 checks met

Layer 1

Recognised DPG

Layer 2

DPI Relevance

Layer 1 Recognised Digital Public Good

Listed in the DPG Registry.
VerifiedVerified DPG logo

Layer 2 DPI Relevance

Does it provide a foundational DPI function, reusable across sectors, at population scale?

Domain fit
Cross-sector reuse
Population scale
3/3

It is a foundational national identity platform, the core of the Digital Identity domain. A national ID is used by every sector — banking, health, social protection, telecoms and government services — and the platform is deployed at country scale across several continents.

Layer 3 DPI Architecture Alignment

How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.

A · Interoperability

3/3

Can other systems connect without modifying the core, using documented open standards?

External API docs
Open standards
Open data formats

The design is API-first, with full RESTful API documentation and OpenAPI specifications for every module. Standards adoption spans FIDO2, OAuth 2.0, OpenID Connect, ISO 19794 biometrics, CBEFF and X.509 PKI, with JSON, CBOR and standard biometric formats exchanged against published schemas.

B · Minimalist & Reusable Design

3/3

Is it a modular building block that does one thing well, rather than a monolithic platform?

Modular architecture
Core/app separation
Config-driven adaptability

A microservices architecture makes each module independently deployable and replaceable through technology bundles. The MOSIP platform core is clearly distinct from reference implementations and country-specific applications, and countries swap components through configuration rather than forking.

C · Ecosystem Enablement

3/3

Can other public and private actors build on top of it?

Third-party buildability
External integrations
No vendor lock-in

A partner management system, APIs and SDKs support an ecosystem of biometric device vendors and system integrators, and multiple countries and technology partners build on the platform today. The MPL-2.0 licence, MOSIP Foundation governance and implementation partners across continents rule out single-vendor dependence.

D · Federation Readiness

3/3

Can it run in distributed or federated deployments suited to national infrastructure?

Federated deployment
Data sovereignty
High availability

A cell-based architecture supports linear scaling and independent national instances across hybrid cloud or on-premise deployment. Data never leaves the jurisdiction by design, and the same cell-based approach is what delivers high availability without single points of failure.

E · Security & Privacy at Scale

3/3

Does it meet the security and privacy bar for population-scale infrastructure?

Infrastructure-grade security
Vulnerability disclosure
Privacy by design

Security covers encryption at rest and in transit, role-based access control and comprehensive audit logging within a zero-knowledge architecture, backed by a dedicated security team, regular assessments and a responsible disclosure process. Privacy is engineered in through data minimisation, consent management, tokenisation and zero-knowledge proofs.

Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.

Spot something out of date? Contact the DPGA