NFC chip

The document that is read by holding it near a phone instead of photographing it. What that chip stores, why its content is signed by the issuing authority, and what that changes compared to reading the front.

In short

An NFC chip in an identity document is a microcircuit with an antenna, embedded in the document body, that delivers its content by proximity when held near a reader. NFC is the near-field communication technology also used by contactless payments, which is why a phone with that capability can read the document with no extra hardware.

What makes the chip in an identity document different is not the communication technology. It is what it carries inside: the holder's data, including their photograph in digital format, cryptographically signed by the issuing authority.

A travel document with this chip is called an eMRTD, and its structure is defined by the ICAO 9303 standard. That standardization is what lets the same process read the chip of a passport issued in another country.

What the chip stores

The content is organized in data groups, and not every document uses all of them.

  • Personal data — the same fields printed at the bottom of the MRZ: name, document number, nationality, date of birth, expiration date.
  • The holder's facial image — in digital quality, not the printed reproduction. It is a much better input for a biometric comparison than a photo taken off the plastic.
  • Additional biometric data — some issuers include fingerprints or iris images, with access restricted through separate mechanisms.
  • The security object — the piece that contains the hash values of the other data groups and the issuing authority's signature over them. It is what turns the chip into evidence.

That last point is what matters. The other groups are data; the security object is the proof that this data came from the registry that claims to have issued it and was not modified since then.

Why the signature changes the nature of the check

Reading the front of a document answers one question: what the document says. Verifying the chip answers another: who said it.

When a process reads the front and extracts the data with OCR, what it gets is a transcription. Authenticity, along that path, is assessed through visual cues: the security features of the physical document, typographic consistency, the absence of tampering marks. They are solid cues, and they are cues.

With the chip, the check is of a different kind. The issuing authority signed the data with its private key, and that signature is verified against the issuing country's certificate. If the verification succeeds, two things are established without relying on judgment: the data is what that registry issued, and no one altered it afterward.

That has a practical effect on document fraud. Altering the printout stops working: if the front shows one date of birth and the signed chip shows another, the check fails, and forging the signature requires the issuing authority's private key.

There are also mechanisms aimed at a different problem: checking that the chip is the original chip and not a copy of its data dumped onto another circuit. These are controls separate from the signature and answer the question of cloning, not of integrity.

What it takes to read the chip

Reading is not automatic, and it is worth knowing its conditions before designing a flow around it.

  • A document that has one — current versions of the same national document exist both with and without a chip. The process has to handle both cases.
  • A key derived from the document itself — the chip does not hand over its content to just anyone who gets near it. Access requires a key built from data printed on the document, usually the MRZ. Without having the physical document in hand there is no reading, and that is the point of the design.
  • A device with NFC and a user who gets the position right — the antenna of the phone and the one in the document need to line up. It is the main source of real friction in this method.
  • Access to the issuing country's certificates — verifying the signature requires the certificate of the authority that produced it. Without that material, the chip gets read but the signature does not get checked, which is keeping only half the value.

A detail that gets confused often: not every chip in a document is a proximity chip. Some documents in the region carry a contact chip, which requires inserting the card into a physical reader and cannot be read with a phone. The chip's technology decides what equipment can read it, and therefore whether it works in a remote onboarding.

Frequently asked questions

It is a microcircuit with an antenna embedded in the document, which delivers its content by proximity when held near a reader or a compatible phone. It stores the holder's personal data and facial image in digital format, with a cryptographic signature from the issuing authority over that set. In travel documents, its structure is defined by the ICAO 9303 standard and the document is called an eMRTD.

That it lets you check authenticity and not just content. Reading the front returns a transcription of what is printed, and authenticity is assessed through visual cues. Verifying the chip lets you check, against the issuing country's certificate, that the data is what that registry issued and that no one modified it afterward. It also provides the facial image in digital quality, which is a better input for biometric comparison than a photo of the plastic.

Not in every case. It takes a device with active NFC capability, a document that carries a proximity chip rather than a contact one, and an access key that is derived from data printed on the document itself, which means it must be physically present. In practice, the most common friction is not technical but positional: the antenna in the phone and the one in the document need to line up during the read.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo