Korean Identity Verification (PASS) Guide
How Korean phone identity verification works: PASS, NICE and KCB contracts, the web flow, CI and DI, legal triggers and users without Korean phones.
In Korea, "identity verification" on a website usually means mobile phone verification: the user confirms through their carrier, often in the PASS app, that the phone in their hand is registered in their own name. Websites do not connect to the carriers directly: they contract an identity verification provider such as NICE or KCB, which asks for a Korean business registration certificate, then open the provider's verification window and receive the verified name, date of birth, phone number and two identifiers, CI and DI.
This guide explains what PASS is, when a Korean service needs verification, how the provider contract and the web flow work, and what to do about users who do not have a Korean phone. It is written for developers and product owners, and it is not legal advice: whether verification is legally required for your service is a question for Korean counsel.
What is PASS, and what is carrier identity verification?
PASS is the authentication app that Korea's three mobile carriers publish: PASS by SKT, PASS by KT and PASS by U+. SK Telecom's App Store listing describes it as providing identity verification, the PASS certificate and mobile ID alongside other services, and states that it can be registered and used only on a phone in the user's own name.
Carrier verification does two checks at once: that the phone number is registered to the person whose name and birth date were entered, and that the person actually holds that phone. NICE's product page describes three ways to complete it:
| Method | What the user does |
|---|---|
| PASS app on a PC | Scans a QR code shown in the verification window with the PASS app |
| PASS app on mobile web | The verification window opens the PASS app automatically |
| SMS | Enters the code sent by text message, after entering their name and details |
The user first chooses their carrier and agrees to the terms in the verification window. PASS approval uses a PIN or biometrics in the app, which NICE describes as more secure than SMS.
Why does Korea use this instead of ID numbers?
Because websites are generally not allowed to collect resident registration numbers. Article 23-2 of the Network Act prohibits information and communications service providers from collecting and using users' resident registration numbers except in narrow cases, the first being a provider designated as an identity verification agency under Article 23-3. Those agencies offer "alternative means" of confirming identity without the number.
Article 23-3 gives the designating role to the Korea Media and Communications Commission (방송미디어통신위원회), the name in force since the amendment of 1 October 2025; older documents say Korea Communications Commission. It assesses applicants' security measures, technical and financial capacity and facilities. Article 23-5 defines connecting information (연계정보, CI) as the irreversibly encrypted form of the resident registration number and limits when agencies may generate and provide it.
The result: a website receives a stable identifier for a person (CI) without ever handling the ID number itself.
When does a Korean service need identity verification?
Some cases are legal duties, others are business choices.
- Age-restricted content and goods. Article 16 of the Youth Protection Act requires anyone selling, lending or providing media designated as harmful to minors to check the other party's age and identity. NICE notes that online adult verification can only be done with the identity verification methods designated under the law.
- Duplicate accounts. Services that give one benefit per person (sign-up coupons, trial periods, one vote, one application) use DI to stop the same person signing up twice.
- Account recovery. Finding a user ID or resetting a password after identity verification avoids relying on an email address that may be lost.
- Regulated sectors. Finance, telecommunications, gaming and some public services have their own rules. Read the sector law or ask counsel; do not infer it from what competitors do.
If nothing in your service requires a legal identity, consider not adding verification at all. It adds friction at sign-up, it excludes people without a Korean phone, and it means handling more personal data.
How do you get an identity verification contract?
Most sites use one provider that covers all carriers. NICE (NICE Information Service) and KCB (Korea Credit Bureau, through its OK-name service) both offer mobile phone verification, and KCB also lists card and i-PIN verification. NICE publishes its onboarding steps:
- Application. Fill in the application form the NICE contact sends, and return it with the terms of use and a copy of your business registration certificate.
- Registration and module. System registration takes up to one business day. The development module is sent to your developer's email, and billing documents to your accounts contact.
- Integration. NICE says integration with your developer takes three to four hours on average.
- Testing, then live service.
NICE also asks for a billing contact who receives tax invoices, and warns that a wrong contact can lead to missed invoices and arrears. Plan the provider fees into your operating costs.
The business registration requirement is the main hurdle for foreign companies. If you have no Korean entity, ask the provider directly whether it can contract with your overseas company before you design the feature.
What does the web and app flow look like?
Provider modules differ in detail, but the shape is the same:
- Your server prepares the request. It creates a request with your site code, a unique request ID and your return URL, encrypted or signed with the keys from the provider's module. Keep these keys on the server only.
- The browser opens the provider's window. On desktop this is usually a popup; on mobile web it may be a full-page redirect. Inside, the user picks a carrier, agrees to the terms and approves in PASS or by SMS.
- The provider returns to your URL. The response carries the encrypted result.
- Your server decrypts and checks it. Confirm the request ID matches the one you created for this session, check the result code, and only then trust the data.
- You act on the result. Create or link the account, mark the user as adult-verified, or continue the transaction.
According to NICE, a successful verification can return name, gender, date of birth, a domestic or foreign national flag, carrier, phone number, CI and DI, depending on what you choose. Collect only the items you need, and list each one in your consent form: NICE states that the items you collect must appear in your consent for collection and use, and that it may ask for supporting evidence.
Apps. In a native app, the verification usually runs in a web view. Test that the PASS app can open from the web view and return to it on both Android and iOS, because that hand-off is where app integrations fail.
What are CI and DI?
Both are derived from the resident registration number, so neither reveals it.
| CI (connecting information) | DI (duplicate-registration information) | |
|---|---|---|
| What it is | Encrypted identifier for a person, defined in Article 23-5 of the Network Act | Identifier combining the person with your site's business code |
| Same across services? | Yes, the same person gets the same CI everywhere | No, each site gets a different DI for the same person |
| Typical use | Linking a person's records where the law allows it | Preventing duplicate sign-ups within your service |
| Handling | Treat as sensitive personal data; store only if you need it | Store with the account to detect repeat sign-ups |
NICE describes CI as an 88-byte value. Size your database column from the provider's specification, not from memory, and store only what your use case needs.
What about foreign users without a Korean phone?
Carrier verification only works for someone with a Korean mobile number registered in their own name. Foreign residents with a Korean phone in their name can usually verify, and NICE's result includes a domestic or foreign national flag. A visitor with only an overseas number cannot.
Design for that from the start:
- Make verification conditional. Ask for it only at the step that needs it, such as an adult-only page or a one-per-person benefit, not at sign-up for everyone.
- Offer an alternative path where the law allows one: email verification, Kakao or Naver login for convenience (Kakao and Naver login integration), or card verification at payment.
- Know where there is no alternative. If Korean law requires verification by a designated method, a global document-and-selfie KYC service does not replace it. Explain the limitation to the user rather than letting them fail at the last step.
Testing and going live
- Test with real phones on all three carriers and on at least one budget (MVNO) line, because those resell carrier service and can behave differently.
- Test the failure paths: the user closes the window, the PASS approval times out, the name does not match, or the user is under age.
- Check the consent text in Korean against what you actually store.
- Log the request and result IDs so you can answer support questions, and keep the personal data itself out of logs.
- Plan provider fees per verification into your pricing.
In our estimator (pricing catalogue v1.1, 23 September 2026), adding phone identity verification to a site we build is KRW 0.6M–1.2M excluding VAT, with three to four development days. Provider fees are passed through at cost. Related integrations are covered in Korean address search API and Korean payment gateway integration.
Frequently asked questions
What is the Pass app used for?
PASS is the carriers' authentication app in Korea. Users approve identity verification requests from websites and apps, and it also offers the PASS certificate and mobile ID. It can be registered only on a phone in the user's own name.
Can foreigners use PASS?
Foreign residents with a Korean mobile number registered in their own name can generally use carrier verification, including PASS. People with only an overseas number cannot, so services with foreign users need an alternative path where the law permits one.
Do I need a Korean business to use identity verification?
In practice, usually yes. NICE asks for a business registration certificate with its application. If you only have an overseas entity, ask the provider whether it can contract with you before planning the feature.
What is the difference between CI and DI?
CI identifies a person consistently across services and is defined in the Network Act as the irreversibly encrypted resident registration number. DI is specific to your site, so it is used to stop the same person from registering twice.
Is phone verification legally required for adult content in Korea?
The Youth Protection Act requires age and identity checks for media designated as harmful to minors, and NICE notes that online adult verification must use designated identity verification methods. Confirm what applies to your service with Korean counsel.
Sources
All checked October 2026.
- Korea Ministry of Government Legislation, Network Act (Articles 23-2, 23-3 and 23-5)
- Korea Ministry of Government Legislation, Youth Protection Act (Article 16)
- NICE ID, Mobile phone identity verification (Korean) and Service procedure (Korean)
- KCB, OK-name identity verification (Korean)
- App Store, PASS by SKT, PASS by KT and PASS by U+
- NQ Solution pricing catalogue v1.1 (23 September 2026)
Planning verification for your Korean service
Before you build anything, it helps to settle three things: whether you need verification at all, at which step, and which entity will contract the provider. Send us your sign-up and payment flow and we will mark where verification belongs and where an alternative path is needed. We also support the Korean-side application with the provider, while the contract stays in your company's name. The Korea integrations page lists the services we connect, and Korea market entry covers the rest of a Korean launch.

