Identity verification is the process by which Login.gov confirms that a user is who they say they are. Some partner agencies require identity verification due to the sensitivity of the data or services users are accessing. This article covers remote unattended and in-person verification, accepted documents, facial matching, proofing rates, reproofing, and common partner questions.
Service Levels
Login.gov offers three service levels:
- Authentication only — Email, password, and MFA. No identity verification. Meets NIST 800-63-3 AAL1 or AAL2 (depending on configuration).
- Basic identity verification — Identity verification without facial matching. Does not meet NIST 800-63-3 IAL2.
- Enhanced identity verification (IAL2) —NIST 800-63-3 IAL2-compliant Identity verification with facial matching (biometrics). Third-party assessed by Kantara Initiative.
For more on service levels and which one is right for your application, see Login.gov’s determining your service level page.
Basic vs. Enhanced: Key Differences
| Feature | Basic Identity Verification | Enhanced Identity Verification (IAL2) |
|---|---|---|
| IAL2 compliant | No | Yes (Kantara assessed) |
| Selfie required (remote) | No | Yes |
| Address verification by mail (remote) | Available if phone verification fails | Not available – phone verification required |
| Phone verification | Required for the in-person option, otherwise optional when verifying address by mail | Required |
Pricing
There is no price difference between Enhanced (IAL2) and Basic IdV services. Login.gov provides competitive pricing for both basic and enhanced identity verification. Contact us for a full breakdown.
Remote Identity Verification
Login.gov’s default identity verification path is remote and unattended — users complete the process from their computer and phone without interacting with a human.
Process Overview
- Document capture: User captures their state-issued ID or U.S. passport book using their device’s camera. photo capture is required and manual upload of scanned images is not permitted.
- Document authentication: Login.gov validates the document’s security features, layout, and data against issuing-source databases.
- Identity resolution: User-submitted attributes (name, date of birth, address, SSN) are verified against authoritative records.
- Phone or address confirmation: User provides a phone number associated with their identity and receives a verification code. If phone verification is unavailable, users in the non-IAL2 flow can verify by mail (5–10 business days).
- Facial matching (IAL2 only): User takes a selfie, which is compared against the photo on their ID.
- Consent and redirect: Upon successful verification, the user consents to share their information with the partner agency and is redirected to the partner application.
For a visual walkthrough, see How to verify your identity on the Login.gov help center.
Desktop to Mobile Handoff
When a user starts identity verification on a desktop, Login.gov texts a link to the user’s mobile device, which when clicked, will initiate the document capture. Once the capture is completed, the user can resume the process on their computer. Mobile capture produces higher success rates because the experience provides real-time feedback on photo quality.
Step-Up Flows
Step up flows are processes where a user upgrades from an authentication-only account to an identity-verified account. Partners can use step-up flows to conditionally enforce identity verification for only a subset of users:
- Default to authentication-only requests for all users.
- After the user is redirected back to your app, determine whether they need verification (based on their role, the information they are accessing, or other criteria).
- If verification is needed, make a second authentication request to Login.gov, this time requiring identity verification.
- Login.gov checks whether the user meets the requested level. If so, they are redirected back immediately. If not, they are prompted to complete verification.
For detailed implementation examples, see Login.gov’s Alternative IdV Playbook (Examples A and B), available from your Partner Success Manager.