Perform NFC chip reading of an ePassport and verify the active authentication and passive authentication certificates per ICAO 9303 Part 11

domain: icao.int · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Establish a Basic Access Control (BAC) or PACE channel to the chip using the MRZ-derived keys (Kenc, Kmac)
  2. Read Data Group 1 (DG1, MRZ data) and Data Group 2 (DG2, face image) using SELECT FILE and READ BINARY APDUs
  3. Read the Document Security Object (SOD) which contains the signed hash manifest and the Document Signer Certificate (DSC)
  4. Verify the DSC chain up to the Country Signing CA (CSCA) certificate obtained from the ICAO PKD or the issuing state's trust anchor
  5. Hash each DG using the algorithm stated in the SOD and compare against the signed hashes to confirm passive authentication

Known gotchas

Related routes

Perform NFC-based passive authentication of an ePassport or eID chip using ReadID to cryptographically confirm the chip's data has not been tampered with
readid.com · 6 steps · unrated
Verify an ePassport's NFC chip using Regula Document Reader's server-side re-verification to confirm eMRTD authenticity
docs.regulaforensics.com · 5 steps · unrated
Read and validate an NFC e-passport chip using ICAO 9303 standards and verify the MRZ
identity-general · 6 steps · unrated

Give your agent this knowledge — and 15,800+ more routes

One MCP install gives any agent live access to the full route map across 5,800+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans