MOSIP
Digital IdentityMOSIP is an open-source platform countries use to build foundational national identity systems, covering enrolment, biometrics, ID issuance, authentication, eKYC and credential management. It is a reference example of identity DPI: API-first, modular, privacy-engineered, and deployed or being deployed in the Philippines, Morocco, Sri Lanka, Ethiopia, Guinea, Togo and elsewhere.
- DPG Profile: https://www.digitalpublicgoods.net/r/modular-open-source-identity-platform
- Website: https://mosip.io/
- Source code: https://github.com/mosip/
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
18 of 18 checks met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment
Layer 1 Recognised Digital Public Good
Listed in the DPG Registry.
Layer 2 DPI Relevance
Does it provide a foundational DPI function, reusable across sectors, at population scale?
It is a foundational national identity platform, the core of the Digital Identity domain. A national ID is used by every sector — banking, health, social protection, telecoms and government services — and the platform is deployed at country scale across several continents.
- Architecture: https://docs.mosip.io/1.2.0/readme/technology/architecture
- MOSIP: https://mosip.io/
Layer 3 DPI Architecture Alignment
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
A · Interoperability
3/3Can other systems connect without modifying the core, using documented open standards?
The design is API-first, with full RESTful API documentation and OpenAPI specifications for every module. Standards adoption spans FIDO2, OAuth 2.0, OpenID Connect, ISO 19794 biometrics, CBEFF and X.509 PKI, with JSON, CBOR and standard biometric formats exchanged against published schemas.
- Architecture & API documentation: https://docs.mosip.io/1.2.0/readme/technology/architecture
B · Minimalist & Reusable Design
3/3Is it a modular building block that does one thing well, rather than a monolithic platform?
A microservices architecture makes each module independently deployable and replaceable through technology bundles. The MOSIP platform core is clearly distinct from reference implementations and country-specific applications, and countries swap components through configuration rather than forking.
- Architecture: https://docs.mosip.io/1.2.0/readme/technology/architecture
C · Ecosystem Enablement
3/3Can other public and private actors build on top of it?
A partner management system, APIs and SDKs support an ecosystem of biometric device vendors and system integrators, and multiple countries and technology partners build on the platform today. The MPL-2.0 licence, MOSIP Foundation governance and implementation partners across continents rule out single-vendor dependence.
- Architecture & partner management: https://docs.mosip.io/1.2.0/readme/technology/architecture
- MOSIP: https://mosip.io/
- Source code (MPL-2.0): https://github.com/mosip/
D · Federation Readiness
3/3Can it run in distributed or federated deployments suited to national infrastructure?
A cell-based architecture supports linear scaling and independent national instances across hybrid cloud or on-premise deployment. Data never leaves the jurisdiction by design, and the same cell-based approach is what delivers high availability without single points of failure.
- Architecture: https://docs.mosip.io/1.2.0/readme/technology/architecture
E · Security & Privacy at Scale
3/3Does it meet the security and privacy bar for population-scale infrastructure?
Security covers encryption at rest and in transit, role-based access control and comprehensive audit logging within a zero-knowledge architecture, backed by a dedicated security team, regular assessments and a responsible disclosure process. Privacy is engineered in through data minimisation, consent management, tokenisation and zero-knowledge proofs.
- Architecture & security: https://docs.mosip.io/1.2.0/readme/technology/architecture
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA