DigiLocker gives people in India a government-operated place to fetch, store, access, and share digital documents. The most important distinction is easy to miss: an issued document comes from an integrated issuer, while an uploaded document is a file you add yourself. Both can be useful, but they do not prove the same thing.
How to Use DigiLocker: Store, Access and Share Your Documents Online
Learn how to create and secure a DigiLocker account, fetch issued records, upload personal copies, share documents safely, verify them, and fix common problems.

This guide explains how to create and protect an account, fetch issued records, upload personal copies, organise files, share only what is needed, verify documents, and recover from common problems. Menu names can change as the website and app are updated, so use the current labels shown in your account and compare them with DigiLocker's official help pages.
Understand the four main areas
The official DigiLocker FAQ describes several account sections. Home shows a summary and routes to other functions. Issued Documents contains links to records provided by government departments or other integrated issuers. DigiLocker Drive contains files uploaded by the user. Activity records actions such as uploads, downloads, and sharing. Browse Documents lists integrated issuers and available document types.
An issued document is fetched from the original issuer's data source and represented in the account by a URI, or Uniform Resource Identifier. An uploaded file is a PDF or image that you selected from your device. Uploading a scan does not turn it into an issuer-provided record. When a bank, university, employer, police officer, or government office asks for a DigiLocker document, confirm whether it accepts the issued record, an uploaded copy, or another format.
DigiLocker's About page states that issued documents in the system are treated at par with original physical documents under Rule 9A of the applicable Digital Locker rules. That statement concerns the issued-document system. It should not be expanded into a claim that every personal upload will be accepted for every purpose.
Prepare before creating the account
Use the official website at https://www.digilocker.gov.in/ or the official app listing reached from that site. Check the domain carefully. Search adverts, forwarded messages, and lookalike login pages can lead to phishing sites. Bookmark the correct address rather than relying on a new search every time.
Keep your Indian mobile number available because signup and sign-in can require a one-time password. If you plan to connect Aadhaar, confirm that you can receive messages on the mobile number registered with Aadhaar. Do not send your Aadhaar number, OTP, security PIN, password, or recovery information to anyone offering setup help.
Choose a private device and a trusted network. Update the browser or app first. Avoid creating the account on a shared computer where downloads, browser history, or saved credentials may remain after you leave. If you must use a shared device, do not save the password and remove downloaded files before signing out.
Decide which documents you need. Collect the identifiers required by the issuing department, such as a registration number, roll number, or year. Entering repeated guesses can waste time and may trigger additional checks. Use the details exactly as they appear in the issuer's record.
Create the DigiLocker account
Open the official DigiLocker site or app and choose Sign Up. The FAQ states that signup can begin with a mobile or Aadhaar number. Follow the current form, request the OTP, and enter it only in the official DigiLocker screen. DigiLocker says its OTP is valid for ten minutes, although you should always follow the timer shown in the current interface.
Set the security PIN requested for two-factor authentication. Do not reuse a banking PIN, phone unlock code, or another important credential. Store it in a reputable password manager rather than a note labelled DigiLocker PIN. If the system asks for a username, remember that the current FAQ says sign-in can use a mobile number or Aadhaar without needing the old username.
Review the profile details after signup. If information fetched from Aadhaar is wrong, DigiLocker cannot edit the Aadhaar record itself. The official FAQ directs users to update Aadhaar through UIDAI and then refresh the linked data. The Tutorils guide to updating Aadhaar details explains how to start with the official UIDAI channels.
Sign out once and complete a fresh sign-in test before adding documents. This confirms that you know the correct account, mobile number, PIN, and recovery path. It is better to discover an access problem now than when a document is urgently required.
Link Aadhaar only through the official flow
Aadhaar linking can help fetch certain records and complete identity checks, but the exact need depends on the issuer and document. DigiLocker's terms describe Aadhaar use as voluntary for authentication on the platform. Follow the current official prompt and read the consent screen before continuing.
The mobile number registered with Aadhaar must be able to receive the Aadhaar OTP for the normal linking path. If that number is outdated, use official UIDAI support or an Aadhaar centre rather than asking an intermediary to receive the OTP. Tutorils also has a guide to linking PAN with Aadhaar, which is a separate tax process and should not be confused with connecting Aadhaar to DigiLocker.
Check the name and date of birth shown after linking. A mismatch between Aadhaar and an issuer's database can prevent a document from being fetched. Do not change spellings at random inside repeated requests. Identify which authority owns the incorrect source record and use that authority's correction process.
If DigiLocker reports that Aadhaar is already registered, do not create more accounts. The FAQ advises recovering the first account with the Aadhaar-based sign-in or recovery option. Multiple accounts can make it harder to know where issued documents and activity records are stored.
Fetch an issued document
Open Browse Documents or the current equivalent. Select the issuing department or search for the document type. Choose the correct record, then enter the identifiers requested by that issuer. Read the consent statement before allowing DigiLocker to fetch the document.
The required fields vary. A school certificate may ask for a year and roll number. A driving licence or vehicle registration may use details held by the transport authority. The issuer, not DigiLocker, controls the source record. Enter the information exactly and submit once.
After a successful fetch, open Issued Documents and confirm that the new entry appears. Check your name, document number, issuer, date, and other visible details. If anything is wrong, do not edit a downloaded copy and present it as corrected. Contact the issuing department and follow its correction procedure.
Download a copy only when you need one, and store it in an encrypted or access-controlled location. A document kept in Issued Documents can often be accessed again through the URI, while an unprotected PDF copied into a messaging folder may remain on several devices.
For driving licence and registration records, the DigiLocker FAQ says the name in Aadhaar should match the name in the transport database. It also explains that a missing record in the National Register cannot be fetched through DigiLocker. That problem must be resolved with the relevant transport record rather than by repeatedly reinstalling the app.
Upload a personal document to DigiLocker Drive
Use DigiLocker Drive or Uploaded Documents when no integrated issuer record is available and you want a personal copy. Select Upload, choose the file from your device, and wait for the upload to complete. Rename the file clearly and assign the document type when the interface allows it.
The FAQ currently lists PDF, JPEG, and PNG as supported upload formats with a maximum file size of 10 MB. Limits can change, so check the current upload screen before compressing an important document. Keep text readable. Heavy compression can make seals, dates, signatures, or small print impossible to inspect.
Scan the entire document, including the reverse side when it contains information. Remove unrelated pages and check orientation. Do not upload another person's record unless you have lawful authority and a genuine reason. DigiLocker's terms state that users remain responsible for the content they upload.
Give files names that make sense without exposing unnecessary identifiers. University-degree-2024.pdf is easier to recognise than scan0042.pdf. Avoid placing a complete Aadhaar number, bank number, or other sensitive identifier in the filename because filenames may appear in lists, notifications, or support screenshots.
Remember the evidence difference. An uploaded photograph of a licence is a user-provided copy. The issued licence fetched from the transport authority is an issuer-linked record. Choose the one the requesting organisation asks for.
Organise documents for quick, safe access
Use consistent names and document types. A simple pattern can include the document name, issuer, and year without a full sensitive number. Remove accidental duplicates after confirming which version is current. Do not delete an issued record merely because you downloaded a PDF.
Review the Activity section after fetching, uploading, downloading, or sharing. It can help you confirm what action occurred and when. If the history shows activity you do not recognise, change account credentials through the official process, review connected sessions if available, and contact DigiLocker support.
Keep a separate emergency plan for documents needed during travel, a hospital visit, an examination, or an outage. DigiLocker depends on account access, device power, connectivity, and the service being available. A protected offline copy or required physical original may still be appropriate. Check the rules of the organisation or journey before leaving.
The Tutorils guide to downloading and sharing government documents safely explains how to name, store, redact, and transfer sensitive files without scattering copies across messaging apps.
Set a calendar reminder to review important records after renewals or corrections. DigiLocker is not the authority that updates every source database. Fetch or refresh the record after the issuer confirms a change.
Access and download a document safely
Sign in through the official app or site and open Issued Documents or DigiLocker Drive. Before downloading, confirm that you selected the intended record and current version. A similar name or old upload can be easy to choose under pressure.
Download only to a device you control. On Android or iPhone, check where the browser or app saves files. On a computer, move the file from Downloads into a protected folder and remove unwanted duplicates. Do not leave sensitive PDFs in a public desktop folder, shared cloud folder, or automatic photo backup without understanding who can access them.
Open the file and check that every page renders. Verify the issuer name, identifiers, dates, digital signature information, and QR code where present. Do not crop or edit an issued document. If an organisation requires a particular export or share method, follow its current instructions.
When printing, use a trusted printer. Office or shop printers may keep temporary files or job histories. Collect every page and ask for deletion when the service supports it. A printed copy still contains the same sensitive information as the digital file.
Share the minimum document required
Ask the recipient what document and format it needs, why it needs it, and how long it will retain the copy. A request for identity proof does not automatically justify sending every record in the account. Select the least sensitive acceptable document.
Use DigiLocker's current Share function or the requesting organisation's official DigiLocker consent flow when available. Check the recipient name and destination before confirming. DigiLocker's terms say users must explicitly consent before fetching or sharing documents, and that consent activity is logged. Read the current screen rather than approving a request from a phone call alone.
Avoid posting document links, QR codes, screenshots, or download files in public groups. A private message is not automatically secure or temporary. Files may be backed up, forwarded, indexed on a device, or left in a media gallery. Use an official upload portal when a trusted organisation provides one.
Redact only when the recipient accepts a redacted user copy and the purpose permits it. Never alter an issued document and represent it as the original. Keep the original separate and label a redacted copy clearly.
After sharing, review Activity and retain the receipt or reference needed for your own records. If you sent the wrong document, contact the recipient immediately and follow its privacy incident process. Deleting a local message may not remove a copy already downloaded by someone else.
Verify a DigiLocker document
Verification checks whether the record came from the claimed issuer and remains intact. The method depends on the document and recipient. DigiLocker describes issued records as digitally signed and may provide a QR code, digital signature, URI, or requester verification flow.
Use the verification function in the official DigiLocker app or the official portal named by the issuer. Do not scan a sensitive QR code with an unknown website or random QR app. For driving licence and vehicle registration records, the DigiLocker FAQ refers to the in-app QR scan facility and validation of the transport authority's digital signature.
A successful QR scan does not mean every visible statement outside the verified record is trustworthy. Confirm the issuer, holder, document type, and current status required for the transaction. An expired or superseded document can still be genuine but unsuitable for the present purpose.
Organisations should use authorised requester or issuer verification channels rather than asking a person to email repeated screenshots. Individuals should be cautious when someone claims that a payment, PIN, OTP, or remote-control app is needed to verify a document.
Fix common DigiLocker problems
If an OTP does not arrive, wait for the current timer, confirm mobile service, and request another OTP through the official screen. Avoid rapid repeated requests. DigiLocker notes that temporary service or SMS delivery problems can occur. Never read the OTP to a caller claiming to fix the delay.
If account details do not match Aadhaar, verify the source record with UIDAI. DigiLocker displays fetched Aadhaar data and cannot make the underlying correction. If an issuer record does not match, use that issuer's correction process.
If a document cannot be found, confirm that you selected the correct issuer and document type, then check every identifier. The source agency may not have integrated that record, the record may not exist in its connected database, or the name and number may differ. Uploading a scan can keep a personal copy, but it does not repair the issuer database.
If the old mobile number is lost, use the current official recovery options. The DigiLocker FAQ describes an Aadhaar OTP path when the user still controls the mobile number registered with Aadhaar. If that path is unavailable, use the official support channel rather than creating an account through an agent.
If you suspect account access by someone else, change the security PIN or credentials, review activity, remove unrecognised access where the interface permits it, protect the email and mobile accounts connected to recovery, and contact DigiLocker support. The Tutorils guide to using passkeys safely also explains broader account-recovery planning, although DigiLocker itself may use different authentication methods.
Protect privacy on the phone and computer
Use a device lock and keep the operating system and DigiLocker app updated. Hide sensitive notification previews on the lock screen. Do not allow a repair shop, remote-support caller, or screen-sharing app to view an open document wallet.
Treat downloaded files separately from the DigiLocker account. A secure account cannot protect a PDF copied into an open folder or forwarded to the wrong chat. Search the device for old copies after completing an application, then keep only the records you genuinely need under appropriate protection.
Do not photograph the account screen merely for convenience. Screenshots can enter automatic photo backups and may include a name, QR code, account detail, or document number. Use the official download or share method when possible.
Review permissions granted to the app and browser. Remove access that is not required, but understand that blocking storage or camera access may disable an upload or QR function. Change one permission at a time and test the needed task.
A repeatable DigiLocker checklist
Before fetching, confirm the official domain or app, account access, mobile number, issuer, document type, and exact identifiers. Read the consent screen.
After fetching, check that the record appears in Issued Documents and that the name, number, issuer, and dates are correct. Resolve errors with the authority that owns the source record.
Before uploading, scan every required page, keep the file readable, remove unrelated information, use a safe filename, and remember that an upload remains user-provided.
Before sharing, confirm the recipient, purpose, minimum acceptable record, destination, retention expectations, and whether an official DigiLocker request is available. Review Activity afterwards.
For long-term access, test sign-in and recovery, protect the connected mobile and email accounts, keep an appropriate offline fallback, and review records after renewal or correction.
DigiLocker is most useful when you understand where a document came from and control where it goes next. Fetch issued records from the correct authority, label personal uploads honestly, and share the smallest acceptable record through a trusted path.
Reader answers
Frequently asked questions
Open a question to read the answer. Opening another answer closes the previous one.
What is DigiLocker used for?
DigiLocker lets users in India fetch issued digital records, store personal uploads, access documents, and share them with consent. Issued documents and user-uploaded copies are different.
How do I create a DigiLocker account?
Use the official website or app, choose Sign Up, enter the requested mobile or Aadhaar number, complete OTP verification, and set the security PIN shown by the current interface.
What is the difference between issued and uploaded documents?
Issued documents come from an integrated issuer's source and appear through a URI. Uploaded documents are files added by the user and do not become issuer-provided records.
Is Aadhaar required to use DigiLocker?
DigiLocker's terms describe Aadhaar as voluntary for authentication, but some document-fetching or identity flows may require Aadhaar linking. Check the current requirement for the specific issuer and record.
Which files can I upload to DigiLocker?
The official FAQ currently lists PDF, JPEG, and PNG with a 10 MB maximum per upload. Check the current upload screen because supported formats and limits can change.
Are DigiLocker documents legally valid?
DigiLocker states that issued documents are treated at par with physical originals under the applicable Digital Locker rules. Confirm what the requesting organisation accepts for the specific transaction.
How do I share a DigiLocker document safely?
Use the current official Share or requester-consent flow, confirm the recipient and purpose, send only the required record, and avoid public groups, unknown portals, or unsolicited verification requests.
How can I verify a DigiLocker document?
Use DigiLocker's official verification method or the issuer's authorised portal. Depending on the record, verification may use a QR code, digital signature, URI, or requester flow.
Why is my document not appearing in DigiLocker?
Check the issuer, document type, identifiers, and name match. The source record may be missing or unavailable through the integration. Contact the issuing authority for source-data corrections.
What should I do if I lose my registered mobile number?
Use the current official recovery options. If Aadhaar recovery is available and you control the Aadhaar-registered mobile number, follow that flow. Otherwise contact official DigiLocker support.