Compare

Choosing a passport OCR API: what to check

When choosing a passport OCR API, check how it proves the fields it returns — not only whether it returns them. The key questions are whether MRZ check digits are verified on the server, whether each field says what evidence backs it, what happens to a field that cannot be confirmed, and how long your documents are kept.

What to check

What to checkWhy it mattersMahad OCR
MRZ check digits verifiedCheck digits catch misread numbers and datesYes — ICAO 9303 digits for number, birth date, expiry and the composite, on the server
Evidence per fieldTells you which values you can use without a second lookYes — field_evidence and fields[].evidence (mrz_checksum, reader_agree, single_reader …)
Unconfirmed fieldsA wrong value accepted silently is the costly failureMarked ⚠; a disputed value is never put in values and the document goes to review
Expired documentsExpiry is a business rule, not an OCR resultExpired → review with the reason “Document expired”
Poor photosGuessing from a blurred photo creates errorsGlare, heavy blur and cut-off edges return “retake” (rescan)
File types and sizeYour capture flow must fitPNG, JPG, PDF, Word; 10 MB; PDF first 5 pages
Async and webhooksLong reads should not block your request202 + polling; webhooks (v2 jobs with per-endpoint signing secrets)
Data retentionPassports are sensitive personal dataOriginals 30 days, results 90 days; delete any time via the API
Government or chip checksOCR alone cannot confirm a document was issuedNot offered — no database lookup, no NFC chip reading, no face match
Trying before buyingTest with your own documentsFree Sandbox plan (50 documents a month) and a live demo

How to test any passport OCR API

Use your own real-world captures — phone photos in the light your users have, not only clean scans. Include an expired passport, one with glare over the MRZ and a PDF with several pages, and look at what each API does with the fields it cannot confirm.

When Mahad OCR is not the right choice

  • You need to confirm a passport with the issuing government or read the NFC chip — Mahad OCR does neither.
  • You need liveness or face matching against the passport photo — not offered.
  • You need an on-premises installation with no network access — Mahad OCR is a hosted API.

Frequently asked questions

What is the most important thing to check in a passport OCR API?

How each field is backed. An API that verifies MRZ check digits and marks unconfirmed fields lets you automate the safe cases and send only the rest to a person.

Do all passport OCR APIs verify MRZ check digits?

Check each provider’s documentation. Mahad OCR recomputes them on its own server for every passport with a readable MRZ.

Can OCR prove a passport is real?

No. OCR and check digits show the data was read correctly. Confirming issuance needs the issuing authority or the chip, which Mahad OCR does not offer.

How should I compare pricing?

Compare the cost per document you actually keep, including the documents that need a person. Mahad OCR’s plans are on the pricing page; the Sandbox plan is free for 50 documents a month.

What should happen to an expired passport?

It should not be accepted silently. Mahad OCR sends it to review with the reason “Document expired”.

Related