Skip to main content
The machine-readable zone (MRZ) is the two or three lines of capital letters, digits and < signs at the bottom of a passport’s photo page, or on the back of many ID cards. It isn’t a barcode. It’s printed text in a font called OCR-B, designed to be read by text recognition, and it repeats the document’s key details in a fixed layout. It’s in the barcode reference because apps that scan ID barcodes usually need it too.

Where you’ll see it

Layout

This is the MRZ of ICAO’s specimen passport, issued by the fictional state of Utopia:
The < sign is a filler. It stands for a space, separates surname from given names (<<), and pads each field to its full length.

First line

Second line

ID cards (TD1) carry the same fields on three shorter lines, in a different order.

Check digits

Each key field has its own check digit, and a final composite check digit covers several fields together. All use the same method:
  1. Give each character a value: digits are themselves, A to Z are 10 to 35, and < is 0.
  2. Multiply the values by 7, 3, 1, 7, 3, 1 and so on.
  3. Add the results. The last digit of the total is the check digit.
For the document number L898902C3: The total is 316, so the check digit is 6. The composite check digit runs over the document number, date of birth, expiry date and optional data, each with its own check digit, in that order.

Reading it reliably

Text recognition has problems barcodes don’t. The check digits are what catch them:
  • Similar characters. 0 and O, 1 and I, 8 and B, 5 and S. A misread almost always breaks a check digit.
  • Glare. Passport pages and ID cards are laminated. Tilt the document slightly so the light doesn’t wash out the text.
  • Partial reads. All lines must be fully in view. A camera that cuts off the last character loses the composite check digit.
  • Holographic and printed backgrounds behind the text, on some documents.
Never accept an MRZ whose check digits don’t all match.

Handling the data

An MRZ is personal data: name, nationality, date of birth, document number. Read only the fields your app needs, don’t log the raw text, and don’t keep it longer than you need it. Some countries regulate collecting identity document data. Check the rules where your app is used.

Gotchas

  • Names aren’t exact. They’re transliterated into A to Z and cut short if they don’t fit, so the MRZ name may not match the printed name.
  • Two-digit years. 74 could be 1974 or 2074. For a date of birth, assume the past. For an expiry date, assume the future.
  • The document number can contain letters. Don’t store it as a number.
  • Optional data varies by country. It may be a personal number, or empty.

Scanning it in your app

Reading an MRZ needs text recognition, so it isn’t available on every reader. The MRZ is in the ID and documents group.

Specification