Perform NFC-based passive authentication of an ePassport or eID chip using ReadID to cryptographically confirm the chip's data has not been tampered with
domain: readid.com · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗
Steps
Integrate the ReadID SDK into a mobile app and use the MRZ (or a scanned document image) to derive the access key needed to unlock the NFC chip
Prompt the user to tap their NFC-enabled phone against the document's chip per ICAO 9303 (eMRTD) requirements
Read the chip's data groups and the Document Security Object (SOD) without needing further interaction with the chip (passive authentication)
Verify the SOD's digital signature chain and compare data group hashes to detect any modification of the stored biographic/biometric data
Where supported by the chip, additionally run Active Authentication or Chip Authentication to detect a cloned chip
Combine the verified chip photo with a live selfie for a face-match step to bind the document to the person presenting it
Known gotchas
Passive authentication confirms data integrity via signature verification, but full trust still depends on validating the issuing country's certificate against a trust anchor (e.g., a PKD) — without that, a self-signed or unknown-issuer SOD can still verify internally while being untrustworthy
Not all documents expose Active or Chip Authentication; older documents may only support passive authentication, so a chip clone can go undetected on those documents
Give your agent this knowledge — and 15,500+ more routes
One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?