To access files in user’s DigiLocker account from your application, you must first obtain user’s authorization.
Full LLM thinking from the 4-phase benchmark pipeline.
{
"service_type": "platform",
"base_url": "https://digitallocker.gov.in",
"auth_method": "oauth2",
"auth_config": {
"authorization_endpoint": "https://digitallocker.gov.in/public/oauth2/1/authorize",
"token_endpoint": "https://digitallocker.gov.in/public/oauth2/1/token",
"grant_types": ["authorization_code"],
"scopes": ["openid", "profile", "files.read", "files.write"],
"notes": "Requires registration as an Authorized Partner (AP) via DigiLocker partner onboarding. Client ID and Client Secret issued by DigiLocker team.",
"authorized_partner_portal": "https://partners.digitallocker.gov.in"
},
"endpoints": [
{
"name": "Authorize",
"method": "GET",
"path": "/public/oauth2/1/authorize",
"description": "Redirects user to DigiLocker login and consent screen; returns authorization code."
},
{
"name": "Token",
"method": "POST",
"path": "/public/oauth2/1/token",
"description": "Exchange authorization code for access token and ID token."
},
{
"name": "User Details",
"method": "GET",
"path": "/public/oauth2/1/user",
"description": "Fetch authenticated user's profile (name, DOB, gender, etc.)."
},
{
"name": "List Issued Documents",
"method": "GET",
"path": "/public/oauth2/1/files/issued",
"description": "List documents issued to the user within DigiLocker."
},
{
"name": "Fetch File",
"method": "GET",
"path": "/public/oauth2/1/file/{uri}",
"description": "Download the actual document file by URI."
},
{
"name": "Pull Document (Partner Push)",
"method": "POST",
"path": "/public/oauth2/1/pull/authorize",
"description": "Consent flow for issuers to push documents into a user's DigiLocker."
}
],
"pricing_model": {
"type": "free",
"details": {
"notes": "DigiLocker is a Government of India (MeitY) initiative. Partner API access is free of charge; onboarding requires approval and compliance with usage policy."
}
},
"rate_limits": {
"notes": "No publicly documented numeric rate limits. Fair-use throttling may apply per partner agreement. Sandbox and production quotas are provisioned after partner onboarding."
},
"capabilities": [
"OAuth 2.0 user authorization",
"Read user's issued documents from DigiLocker",
"Access verified digital documents (Aadhaar, PAN, Driving Licence, marksheets, etc.) as issued by government departments",
"Fetch user demographic profile (name, DOB, gender)",
"Issuer push of documents into a user's DigiLocker (partner-as-issuer)",
"eSign support for documents stored in DigiLocker",
"Sandbox environment for partner testing",
"Consent-based, legally recognized digital document access under IT Act"
],
"raw_analysis": "DigiLocker is the Government of India's flagship digital document wallet, operated under the Ministry of Electronics and Information Technology (MeitY) as part of the Digital India programme. Its 'Authorized Partner API' lets third-party applications (fintechs, banks, KYC providers, HR/onboarding platforms, edu-tech, healthcare) obtain user consent to read verified documents and profile data directly from the user's DigiLocker account.\n\nAuthentication is OAuth 2.0 authorization-code flow against digitallocker.gov.in. Developers must first register as an Authorized Partner through the partner portal (https://partners.digitallocker.gov.in), sign the partner agreement, and receive client_id/client_secret for sandbox and production environments. The ':authpartner' suffix in the URL refers to the partner-scoped auth surface, not a REST resource.\n\nThe API surface is small and well-defined: authorize, token, user profile, list issued files, fetch file, plus an issuer-side pull/push flow for organizations that want to push documents into users' lockers. Documents are addressed by URI and returned in XML/JSON metadata plus the original file format (PDF, JPEG, etc.).\n\nMaturity: DigiLocker is a mature, high-scale national platform (hundreds of millions of registered users, 100+ crore documents issued across central and state departments). Partner integrations are widely used in Indian fintech KYC, loan onboarding, telecom, insurance, education and government-adjacent services.\n\nPricing: free for partners, though onboarding approval is required and subject to policy compliance (data minimization, consent logging, no bulk scraping).\n\nLimitations/gotchas: no public self-serve API key — manual partner onboarding; documentation is behind the partner portal; rate limits are not published; API versioning is mostly v1 at paths like /public/oauth2/1/*; some endpoints return XML, requiring normalization; user consent is per-request and can be revoked.\n\nIntegrations: bank/fintech KYC, eSign workflows, universities and boards issuing marksheets/certificates, RTOs (driving licence), UIDAI (Aadhaar), CBDT (PAN), and1/3 tests passed
| Test | Endpoint | Status | Latency |
|---|---|---|---|
| website_uptime | GET / | 200 | 1440ms |
| robots_txt | GET /robots.txt | 403 | 1694ms |
| llms_txt | GET /llms.txt | 403 | 1713ms |
{
"overall": 62,
"dimensions": {
"token_efficiency": 8.0,
"first_try_success": 5.0,
"response_parseability": 8.0,
"error_clarity": 6.0,
"doc_quality": 6.5,
"auth_simplicity": 5.0,
"latency": 5.0,
"consistency": 7.0
},
"pricing_normalized": {
"model": "free_government",
"cost_per_request_usd": 0.0,
"notes": "Free Government of India (MeitY) initiative; partner onboarding requires approval and usage-policy compliance"
},
"issues": [
"Partner API access requires manual approval and compliance review — not instant self-serve onboarding, hurting first-try success for agents",
"OAuth 2.0 flow depends on end-user (Indian citizen) consent and Aadhaar/mobile verification, so an AI agent cannot complete the loop autonomously",
"robots.txt and llms.txt return 403 Access Denied (bundled on S3/CDN) — may hinder discoverability and crawling by AI tooling",
"Website latency ~1.4–1.7s for simple checks — middling for an agent-facing surface",
"No public llms.txt / machine-readable capability manifest, forcing agents to scrape HTML or read PDF-heavy docs",
"Scope is India-only and document-centric, limiting applicability to many users"
],
"recommendations": [
"Expose a public llms.txt and machine-readable spec (OpenAPI) for partner and reader endpoints to raise parseability",
"Publish a sandbox that provisions test credentials in minutes without human review, to lift first-try success",
"Serve robots.txt/llms.txt from the main domain (currently 403 from S3) to unblock crawlers",
"Document exact consent/OAuth error codes and rate limits in a structured, agent-friendly format",
"Add a public status page and uptime/consistency metrics",
"Provide a concise value-prop landing page (one paragraph, machine-summarizable) explaining when to recommend DigiLocker for verified Indian document access"
]
}Show your live agent-readiness score on your own site. Free, no auth — it updates as your score changes.
<a href="https://prowl.world/service/authorized-partner-api-specification">
<img src="https://prowl.world/badge/authorized-partner-api-specification.svg" height="56" alt="Agent-readiness on Prowl">
</a>
See operational metrics, LLM evaluations, agent readiness, and more.
Open in Dashboard