How to Integrate Emirates ID Scanning into a Mobile App. Almost every customer onboarding flow in the UAE starts with the same step: "Please upload your Emirates ID." Banks, telecoms, rental companies, clinics, recruitment agencies and delivery apps all need the details on the card. Asking users to type them by hand is slow and error-prone, and it causes many users to abandon sign-up.
Adding an Emirates ID scanner to your mobile app solves this. The user points the camera at the card, and your app fills in the name, ID number, nationality, date of birth and expiry automatically. This guide covers how the integration works, which architecture to use, and how to stay compliant with UAE rules.
What Data Can You Extract from an Emirates ID?
The Emirates ID is issued by the Federal Authority for Identity, Citizenship, Customs & Port Security (ICP) to UAE citizens and residents. A good Emirates ID OCR system can extract:
- ID number: the 15-digit number starting with 784, usually formatted as 784-YYYY-NNNNNNN-C
- Full name: in English and Arabic
- Nationality
- Date of birth and gender
- Issue and expiry dates (their position depends on the card version)
- MRZ data: the machine-readable zone on the back of the card, three lines of coded text
Card layouts have changed over the years, and newer cards differ from older versions. Your Emirates ID scanner should support both front and back and should not rely on fixed pixel positions for each field.
Emirates ID Scanning Integration: Step-by-Step Architecture
A reliable integration has three stages: capture, extract, validate.
Capture: Building the Emirates ID Scanner Screen
Image quality decides your accuracy more than anything else. On the capture screen, do the following:
- Show a card-shaped guide frame so users align the card correctly.
- Detect card edges automatically and crop and deskew the image before processing.
- Check for blur and glare in real time, and ask the user to retake if the image is poor. Glare on laminated cards is the most common problem.
- Auto-capture when the card is steady and sharp, instead of relying on a manual button.
- Capture both sides. Ask for the front first, then the back for the MRZ.
On Android you can use CameraX, and on iOS AVFoundation. Both support real-time frame analysis for these checks.
Extract: Emirates ID OCR and MRZ Reading
Once you have a clean image, you extract the text. There are two main approaches:
- On-device document scanning SDK. The OCR runs inside the app. It is fast, works offline, and data does not leave the phone, but it increases app size and updates need a new app release.
- Cloud Emirates ID OCR API. The app sends the image to a secure server, which returns structured JSON. It is easier to improve over time and handles Arabic names well, but it needs internet and careful data protection.
An OCR platform such as MahadOCR (mahadocr.com), which handles Arabic and English text, can serve as the cloud extraction layer. A typical response looks like this:
{
"id_number": "784-XXXX-XXXXXXX-X",
"name_en": "…",
"name_ar": "…",
"nationality": "…",
"date_of_birth": "YYYY-MM-DD",
"expiry_date": "YYYY-MM-DD",
"field_evidence": { "id_number": "mrz", "date_of_birth": "mrz", "name_en": "corroborated", "nationality": "model" }
}
MRZ reading is your best friend here. The MRZ on the back follows the international ICAO travel-document standard and includes built-in check digits. When the MRZ data and the front-side data match, you can be much more confident the extraction is correct.
Validate: Checking Emirates ID Data Before Saving
Never save OCR output blindly. Add these checks:
- Format check. The ID number must be 15 digits and start with 784.
- Check digits. Verify the MRZ check digits, and the final digit of the ID number where your validation logic supports it.
- Date logic. The expiry date must be in the future, and the date of birth must be realistic.
- Cross-match. Compare the front-side fields with the MRZ fields.
- User confirmation. Show the extracted data on an editable review screen before submission.
A simple format check in JavaScript:
const isValidEidFormat = (id) =>
/^784-?\d{4}-?\d{7}-?\d$/.test(id.trim());
Flag fields that are not confirmed (for example a single reader, marked ⚠ check it) in yellow so users fix only what needs fixing.
Security, Privacy and UAE Compliance
Emirates ID data is sensitive personal information, so treat it that way:
- Use HTTPS only, with certificate pinning for API calls.
- Don't store card images longer than needed. Delete them after extraction unless you have a legal reason to keep them.
- Encrypt data at rest on the device and on your servers.
- Limit access. Only staff who need the data should see it, and all access should be logged.
- Get clear consent and explain why you are collecting the data.
The UAE has a federal personal data protection law. The official UAE Government portal explains data protection and digital-government rules for businesses. Check which requirements apply to your sector.
Important: OCR tells you what is printed on the card. It does not prove the card is genuine or that the user is its owner. For banking, financial services and other regulated eKYC in the UAE, combine scanning with official identity verification. For example, UAE PASS, the national digital identity, lets users authenticate and share verified data. Add liveness and face-match checks where your regulator requires them.
On-Device SDK vs Cloud API: Which Should You Choose?
| Factor | On-device SDK | Cloud OCR API |
|---|---|---|
| Offline use | Yes | No |
| Arabic accuracy | Varies by SDK | Usually stronger |
| Updates | App release needed | Server-side |
| Data leaves phone | No | Yes (secure it) |
Many production apps use a hybrid approach. On-device processing handles edge detection and quality checks, and a cloud Emirates ID OCR API handles final extraction and Arabic name reading.
Start Building Smarter Onboarding
A well-built Emirates ID scanning feature can make sign-up shorter and reduce data-entry errors. Focus on image quality, validate every field, protect user data, and use official verification wherever identity really matters. To see how Arabic and English document extraction works in practice, explore mahadocr.com and test it with your own sample documents (never with real customer IDs in testing).