Table of Contents
- The Airport Problem Nobody Talked About
- What Digi Yatra Actually Is
- How Digi Yatra Works in Practice
- The Architecture: Self-Sovereign Identity at Scale
- The Growth Story — and Its Achievements
- What Digi Yatra Gets Right
- The Problems Nobody Talks About
- The Road Ahead: DPI Ambitions and Expansion
- Digi Yatra in the Global Context
- The Verdict
The Airport Problem Nobody Talked About
Every year, over 500 million passengers pass through Indian airports. Each one must prove their identity multiple times — at terminal entry, security check, and boarding gate. Each checkpoint requires fishing out documents, searching for boarding passes, and waiting in queues. For domestic flights, the process is largely the same as it was decades ago: paper tickets, physical IDs, and manual verification.
The old system was built for a world of low passenger volumes. But India's aviation sector is growing exponentially. Daily domestic passenger traffic has crossed the 5-lakh mark on numerous occasions, up from below 2 lakh in 2014. Annual passenger traffic is projected to reach 50 crores by 2030 and double to nearly 100 crores by 2040. At that scale, manual document verification becomes a bottleneck — not just inconvenient, but operationally unsustainable.
India's airports were not designed for a billion-passenger future. Terminal space is finite. Queues compound. Every second spent verifying a piece of paper at a checkpoint is a second that could be spent processing the next passenger. The question was not whether to automate — it was how to automate without building a centralised surveillance state.
Digi Yatra is India's answer to that question.
What Digi Yatra Actually Is
Digi Yatra is not just an app. It is a biometric-based digital travel system that enables paperless, contactless airport entry and boarding using facial recognition technology. Developed by the Ministry of Civil Aviation and the Digi Yatra Foundation, the platform acts as a mobile-based ID storage wallet where travellers can save their identity and travel documents.
Instead of showing your boarding pass and ID at multiple checkpoints, you stand before a camera — and the system verifies you. Terminal entry. Security check. Boarding gate. All through your face.
The transformation is simple but profound: the airport journey becomes seamless, frictionless, and fast. But the real innovation is not the facial recognition — it is the architecture underneath. Digi Yatra is built on a decentralised digital identity architecture using open standards developed by the World Wide Web Consortium (W3C), along with technologies such as Self-Sovereign Identity (SSI), Verifiable Credentials (VC), and Decentralized Identifiers (DID). The underlying principle is privacy by design.
This is not a semantic distinction. A centralised biometric database — the model most countries default to — stores millions of face templates in a government server. One breach compromises everyone. Digi Yatra's decentralised model means your identity stays on your phone. The airport only receives a flight-specific biometric token. And that token is purged within 24 hours of your flight's departure.
It is, by the foundation's own description, one of the largest successful implementations of self-sovereign identity in the world.
How Digi Yatra Works in Practice
The system operates in three distinct phases: one-time registration, per-journey linking, and airport biometric verification.
One-Time Registration
You download the Digi Yatra app and register using your mobile number linked to Aadhaar. After OTP verification, you authenticate through standard e-KYC — UIDAI sends your Aadhaar details to your phone.
The app takes only what it needs: your name, age (derived from date of birth), and gender. It does not store your full Aadhaar number — only a masked version. To validate that you are the person registering, you take a selfie. This is matched against your Aadhaar photo. If they match, a verified credential is created and sent back to your phone, sitting securely in your Digi Yatra wallet.
Everything used to create this credential is immediately purged. "We have no database," says Siddharth Sharma, the chief information and innovation officer of Digi Yatra. The credential exists only on your device.
Before Each Journey
You upload your boarding pass by scanning its QR code or uploading a PDF. The app extracts only the standard details: name, seat number, PNR, day of travel, origin destination, and sequence number. The name on the boarding pass is matched with the name on your verified credential. If they match, the boarding pass is linked.
Between 24 hours and 60 minutes before departure, you share your travel credentials with your departure airport. This data is encrypted and sent directly from your phone to the airport's biometric gallery — not through a central Digi Yatra server, because there is no central Digi Yatra server that holds identity data.
At the Airport
You approach the Digi Yatra e-gate at terminal entry and scan your boarding pass. The camera captures your face and performs a one-to-one match against the biometric data shared with the airport. Once matched, a request goes to the airline system to validate that you are on today's flight. If the confirmation comes back, the gate opens.
The same facial verification is used at subsequent checkpoints — security and boarding — without requiring you to show documents again. The average processing time drops from 15 seconds to 5 seconds per passenger.
Data Deletion
This is the critical part: the data shared with the airport is purged from their biometric gallery within 24 hours of your flight's departure. There is no central repository of passenger data. No database to breach. No identity trail to follow. Your data stays on your phone, and what the airport receives is temporary by design — not by policy, but by architecture.
The Architecture: Self-Sovereign Identity at National Scale
Digi Yatra's architecture is worth understanding because it is different from how most countries build biometric systems. The model follows what cryptographers call a "trust triangle":
The Holder (Passenger). You hold your own credentials on your device. You are not a subject in a database — you are the holder of your own identity data.
The Issuer (Digi Yatra Foundation). The foundation issues you a verified credential after validating your identity against Aadhaar. But it does not retain the data used to issue it. The credential is issued and the underlying data is purged.
The Verifier (Airport). The airport receives your credential, validates it against your face at the e-gate, confirms with the airline that you are on the flight, and then deletes the data within 24 hours.
This three-party model — holder, issuer, verifier — is the core architecture of self-sovereign identity. Each party only holds the data it needs, for only as long as it needs it. No party holds everything.
Journey logs retained for 14 days are not linked to any personally identifiable data. The foundation cannot produce audit trails of who travelled where because it never held that data in the first place. This is either the system's greatest privacy feature or its greatest transparency problem — depending on who you ask.
The Growth Story — and Its Achievements
Digi Yatra's growth has been remarkable. As of mid-2026, the platform has crossed 10 crore (100 million) passenger journeys across 38 airports, with over 2.4 crore app downloads.
Scale
The platform is operational at 38 airports across India, including all major hubs — Delhi, Mumbai, Bengaluru, Hyderabad, Chennai, Kolkata, Kochi, and Ahmedabad among others. The government plans to add 27 more airports by next year, bringing the total to 65.
The app has been downloaded over 19 million times and used over 81 million times. At operational airports, adoption averages around 30% of domestic departing passengers, with several airports reporting significantly higher usage.
Efficiency
Average airport entry processing time has been reduced from 15 seconds to just 5 seconds per passenger. This rapid throughput has significantly optimised terminal infrastructure, reduced congestion, and minimised manual processing overheads.
At Kochi airport, one in every three domestic departure passengers now enters the terminal using Digi Yatra. The airport has the highest boarding adoption rate in the country, with over 7.95 lakh passengers using it in 2025-26 alone.
Environmental Impact
By eliminating physical boarding passes, the initiative saves thousands of sheets of paper daily across participating airports. At 500 million passengers per year, even a fraction adopting digital boarding passes translates to meaningful reductions in paper waste.
What Digi Yatra Gets Right
Despite the complexity of building a national biometric travel system, Digi Yatra has several architectural strengths that set it apart from comparable systems globally.
1. Decentralised Identity Architecture
Your identity data is stored on your phone, not on a central server. This is fundamentally different from centralised biometric databases, where a single breach could compromise millions of records. The architecture treats the passenger as the holder of their own credentials — not as a subject in a government database.
2. Privacy by Design
The system is built to minimise data collection and retention. Only necessary information is shared with airports, and it is purged within 24 hours. This is not a promise — it is how the system is architected. Journey logs retained for 14 days are not linked to any personally identifiable data. The system cannot reveal your travel history because it never stored it.
3. Consent-Based
Digi Yatra is entirely voluntary. You choose whether to use it. You choose when to share your data. You can delete the app at any time, leaving no data trail. Non-users can complete the usual document verification process with airport staff. Unlike Aadhaar — which became de facto mandatory for many services — Digi Yatra was designed with an explicit opt-in architecture.
4. Security Audits
The system's deletion mechanism, potential leak points, and system plugs are audited every year by CERT-In — India's national cybersecurity agency. These audits are not ceremonial. CERT-In tries to break things. Their findings go to departments such as NIC, MeitY, and MoCA. The foundation publishes tenders on its website and voluntarily follows General Financial Rules norms.
5. Interoperability with India Stack
Digi Yatra is designed to work with other Digital Public Infrastructure components — Aadhaar for identity, DigiLocker for documents, and UPI for payments. This interoperability creates a seamless digital experience. You prove who you are with Aadhaar. Your boarding pass comes from DigiLocker or an airline app. You pay for anything at the airport with UPI. Each layer does one thing and interoperates with the others.
The Problems Nobody Talks About
Digi Yatra's expansion has not been without controversy. Several structural issues remain unresolved.
The Privacy Debate
Despite the decentralised architecture, there are legitimate concerns. The system processes facial data — one of the most sensitive forms of personal information. Critics argue that there is no statutory framework governing the deployment of facial recognition in India, and the Digital Personal Data Protection (DPDP) Act, 2023, had not been enforced when Digi Yatra became operational.
The government responds that the system is designed to be privacy-preserving. But the debate continues. Activists demand audit trails as proof of honesty. Digi Yatra cannot provide them because there is no identity data in its backend to audit. This is either a privacy feature or a transparency problem, depending on your perspective. The same architecture that prevents the government from surveilling you also prevents independent auditors from verifying that the government is not surveilling you.
The Legal Structure
Digi Yatra Foundation is a Section 8 not-for-profit private company. The Airports Authority of India (AAI) holds only 26% stake. Private airport operators — Cochin, Bengaluru, Hyderabad, Mumbai, and Delhi — each hold 14.8%. The foundation is not subject to Right to Information (RTI) Act obligations, which limits public oversight.
This is a recurring tension in India's digital public infrastructure: the entity building the infrastructure is structured as a private company, exempt from the transparency obligations that apply to government bodies. Critics argue this makes the system opaque. The foundation argues it voluntarily follows GFR norms. Neither side is entirely satisfied.
The 'Voluntary-but-Mandatory' Concern
While Digi Yatra is officially voluntary, there have been instances where it has been made difficult for passengers not to use it — by reducing non-Digi Yatra gates, both for entry and security check-in. This is a recurring pattern with India's digital public infrastructure: optional in theory, essential in practice. When only one or two manual verification counters serve hundreds of non-Digi Yatra passengers while a dozen e-gates sit mostly empty, the "choice" becomes coercive.
Technical Disruptions
The app suffered multiple outages, including an unannounced migration to a new app that bricked the old one, leaving users stranded at airports. While these issues have been addressed, they reveal concerns about operational maturity and contingency planning. A system that passengers rely on to board flights cannot go dark without warning.
Data Breach in 2024
In April 2024, the app faced a data breach that led the company to urge users to uninstall the app, though it did not explain how the breach happened. For a system whose core promise is privacy by design, a breach — even one that did not expose biometric data — erodes the trust the entire architecture depends on.
The Road Ahead: DPI Ambitions and Expansion
The Digi Yatra Foundation has expressed interest in becoming a recognised Digital Public Infrastructure (DPI) in the next six to nine months. This would require meeting certain criteria — transparency, accountability, public ownership, and genuine openness.
But there is scepticism. Critics argue that before Digi Yatra becomes a DPI, it must be subject to RTI transparency obligations, have a statutory framework governing facial recognition, enforce data protection laws before scaling further, ensure participation is genuinely optional, and maintain neutrality and equal access.
Expansion Beyond Aviation
The foundation envisions implementing facial recognition beyond aviation — for hotel check-ins, IT parks, and even online exams. The Ministry of Tourism is working on a national tourism digital stack that would leverage Digi Yatra, DigiLocker, UPI, and ONDC to enable seamless travel and transactions.
This is controversial. As MediaNama noted, "Digi Yatra might want to expand its scope of operation, but that doesn't mean that a company that handles this kind of sensitive data without oversight and a history of poor governance should be allowed to." The expansion of a facial recognition system from airports to hotels, workplaces, and examination halls raises questions about mission creep that the current legal structure is not equipped to answer.
Technical Upgrades
The platform is working on deeper integration with airlines and booking platforms — enabling passengers to share boarding passes directly from airline apps with a single click. It also plans to introduce support across all 22 regional languages to improve accessibility beyond English and Hindi speakers.
Digi Yatra in the Global Context
India is not alone in exploring biometric travel. Singapore's Changi Airport and China's railway system have successfully implemented biometric-based boarding systems. The European Union is developing a digital travel framework. The United States runs biometric exit programmes at several airports.
But India's approach is architecturally distinct. Most systems are centralised — your biometrics are stored in a government database. Digi Yatra is decentralised — your biometrics stay on your phone. This is a significant architectural choice with implications for privacy, security, and scalability.
A centralised system is easier to build and easier to audit. A decentralised system is harder to compromise at scale and gives individuals more control. The trade-off is real, and the global community is watching which model proves more resilient over time. If Digi Yatra succeeds at scale — 100 million journeys and growing — it validates the decentralised approach in a way that no smaller pilot could.
Recommended tools & resources
If you want to explore digital identity, biometric systems, and travel infrastructure deeper, these resources can help.
Disclosure: Links may be affiliate links. See Disclaimer.
The Verdict
Digi Yatra is neither the privacy nightmare its critics claim nor the seamless solution its supporters promise. It is an infrastructure project in the middle of its most difficult phase — past the initial enthusiasm, not yet at universal coverage, dealing with real problems that have no easy solutions.
The direction is right. An India where 500 million passengers move through airports without friction, fraud, or repeated document checks would be more efficient and more pleasant. The architecture is genuinely innovative — a decentralised identity model at a scale no other country has attempted. And the privacy-by-design principles, if maintained and independently verified, set a standard that other biometric systems should follow.
But the execution has gaps. The legal structure limits transparency. The voluntary nature of the system is under quiet pressure. The 2024 breach and the app migration failures reveal operational immaturity. And the ambition to expand beyond aviation into hotels, workplaces, and exams raises questions that the current governance framework is not equipped to answer.
The old airport system had decades to entrench itself. Digital infrastructure deserves a few years to prove its case. But it will only earn that time if it earns public trust — not through press releases, but through verifiable architecture, independent audits with real teeth, and a governance structure that invites scrutiny rather than evading it.
Digi Yatra represents the same thesis that runs through all of India's digital public infrastructure: that the state's job is to build open, interoperable rails — and let citizens, institutions, and markets build on top of them. The test for Digi Yatra is whether it can deliver on that thesis while handling the most sensitive data of all: the geometry of your face.