Skip to main content
Tuteliq validates documents at three levels: document number algorithms, MRZ check digits, and barcode data extraction. Each layer independently verifies the document’s integrity, and all layers are cross-referenced against each other.

Document number validation

Tuteliq validates document numbers using the actual government-defined algorithm for each country — not just format checks. This means a forged document with a made-up number that looks correct will still fail validation.

Supported countries (45)

Americas (8)

Brazil (CPF), Argentina (DNI), Mexico (CURP), Chile (RUT), Colombia (CC), Peru (DNI), Ecuador (CI), Uruguay (CI), Canada (SIN), United States (SSN)

Europe (22)

Sweden (personnummer), Spain (DNI/NIE), Netherlands (BSN), Portugal (NIF), Germany (Steuer-ID), France (NIR), Italy (Codice Fiscale), Belgium (NRN), Finland (PIC), Norway (fnr), Poland (PESEL), UK (NI Number), Ireland (PPS), Switzerland (AHV), Austria (SVNr), Czech Republic (RC), Romania (CNP), Croatia (OIB), Bulgaria (EGN), Greece (AFM), Hungary (Tax ID), Estonia, Lithuania, Latvia

Asia-Pacific (9)

Thailand (ID), Turkey (TC Kimlik), South Korea (RRN), India (Aadhaar), China (ID), Taiwan (ID), Japan (My Number), Australia (TFN), New Zealand (IRD)

Middle East & Africa (2)

Israel (ID), South Africa (ID)

Validation algorithms

Each country uses a specific check digit algorithm. Some examples:
Document number validation is automatic — when a document number and country code are detected, the appropriate algorithm runs without any configuration.

MRZ validation (ICAO 9303)

The Machine Readable Zone (MRZ) is present on passports and many national ID cards worldwide. Tuteliq implements full ICAO 9303 MRZ parsing with check digit validation.

Supported formats

What gets validated

Each MRZ contains multiple fields, each protected by its own check digit using the ICAO weighted mod-7 algorithm (weights cycle [7, 3, 1]): The composite check digit is critical — even if someone correctly recalculates individual field check digits after altering a value, the composite check will fail unless they also recalculate it.

Extracted fields

When a valid MRZ is detected, Tuteliq extracts and returns:
  • Document number (with validation status)
  • Nationality / issuing state
  • Date of birth (with century detection)
  • Expiry date
  • Sex
  • Surname and given names
  • Personal number / optional data
All extracted fields are cross-referenced against OCR text from the visible part of the document.

PDF417 barcode reading

US and Canadian driver’s licenses encode all personal data in a PDF417 barcode on the back of the card following the AAMVA (American Association of Motor Vehicle Administrators) standard.

Why barcodes matter

The barcode data is independent of the printed text on the front. A forger who edits the front of a driver’s license (changing the name, DOB, or photo) must also modify the barcode — which requires specialized knowledge. Most forgeries only edit the visual side. When both sides are provided, Tuteliq:
  1. Decodes the PDF417 barcode from the back image
  2. Parses AAMVA fields (name, DOB, expiry, license number, sex, address, state)
  3. Cross-references barcode data against OCR text from the front
  4. Flags any mismatch as potential tampering
  5. Falls back to barcode DOB/expiry when OCR fails to extract them

Extracted AAMVA fields

Supported barcodes

For best barcode reading results, provide the back of the document as a separate image using the document_back field. This allows dedicated barcode scanning without the front-side OCR processing interfering.

How the layers work together

Any inconsistency between sources generates a specific failure reason that is included in the API response.

Next steps

Liveness Detection

How visual liveness prevents spoofing attacks.

Fraud Prevention

Multi-layer cross-referencing and authenticity analysis.