Blog01 August 202612 min read2781 words

Turkey Shuts Down the Public T.C. ID Verification Service for Captive Portals

Türkiye's civil registry (NVİ) has permanently closed the free public T.C. ID number verification web services that captive portals relied on for guest Wi-Fi identity checks. This guide explains what changed, why, who may still use the paid KPS alternative, and how hotspot operators can stay compliant with Law No. 5651.

#tc-id-verification#nvi#kps#captive-portal#hotspot#law-5651#sms-otp

1. Executive Summary

Türkiye's General Directorate of Civil Registration and Nationality (NVİ) has closed off programmatic access to the free, publicly available T.C. identity verification web services (the KPSPublic SOAP services) hosted at tckimlik.nvi.gov.tr, which had operated openly for years. The decision to shut them down was taken under Decision No. 2025/4 of the Data Sharing Board, a body established pursuant to Article 45 of Law No. 5490 on Population Services. The shutdown was first announced for 1 August 2025, then postponed to 30 September 2025 because institutions could not complete their integration work in time, and the services were permanently discontinued as of that date.

This service was the identity verification infrastructure most widely used in Türkiye by hotels, cafés, shopping malls, schools, hospitals and other institutions that offer guest Wi-Fi (captive portal / hotspot) under Law No. 5651. The T.C. ID number, first name, surname and year of birth a user entered were verified in real time against this free service before a session was opened. With the service gone, this method stopped working across the country, and the industry quickly moved to alternatives — SMS OTP first and foremost. For organizations that still want to verify identities, the official route is now to register with the Identity Sharing System (KPS) and use the paid, per-query KPSv2 services (subject to a participation fee).

2. What Was the Service That Was Shut Down, and How Did It Work?

The KPSPublic SOAP web services published under tckimlik.nvi.gov.tr (e.g. https://tckimlik.nvi.gov.tr/service/kpspublic.asmx) could be called without any contract, API key or fee. The most commonly used methods were TCKimlikNoDogrula (verifying a citizen by T.C. ID number + first name + surname + year of birth), services for verifying a person and their ID card/wallet, and services for verifying foreign national ID numbers.

In a captive portal scenario, the flow typically looked like this: a user connecting to the guest Wi-Fi network was presented with a portal page where they entered their T.C. ID number, first name, surname and year of birth; the hotspot software verified this information against the NVİ service in real time; if verification succeeded, internet access was granted; and the traffic logs required under Law No. 5651 were stored with timestamps, matched to that verified identity.

The appeal of the service was that it was free, fast and came from an official source. For that reason it was widely used not only in the hotspot industry but also in membership/subscription systems, CRMs, appointment and registration platforms, and e-commerce and education platforms (for example, in contract-generation steps).

3. The Shutdown Decision: Timeline and Legal Basis

The legal basis for the decision is Article 45 of Law No. 5490 on Population Services, which governs the sharing of population data, and the Data Sharing Board established under that article. The Board's Decision No. 2025/4 introduced two key changes: first, the addition of a "Serial No" field to the "Full Registry Verification Service" within KPS (meaning that verification can now also query the ID card serial number — a security enhancement aimed at proving physical possession of the card); and second, the closure of the publicly accessible web-page verification services at tckimlik.nvi.gov.tr.

The timeline unfolded as follows: the shutdown was first announced for 01.08.2025; because institutions' KPS integration work was still ongoing, the date was extended to 30.09.2025; and as of 30 September 2025, programmatic (API/web-service) access was permanently ended. One important detail: the on-screen service at tckimlik.nvi.gov.tr (the form page where individual manual queries are made from a browser, e.g. /Modul/TcKimlikNoDogrula) remained available for citizen use. What was closed is the web services that software could call automatically.

4. Why Was It Shut Down?

The official rationale is the consolidation of identity verification authority in a single center (KPS and the e-Government Gateway) — in other words, centralization. The motivations behind this can be grouped under a few headings.

Data security and the risk of abuse are the foremost factors. Because the service could be called completely anonymously and without limits, it was possible to verify combinations of T.C. ID number + name + year of birth by trial and error (using it as a kind of "oracle"). The large-scale personal data breaches that have persisted in Türkiye for years — the allegations that surfaced publicly in 2023 that e-Government data had been stolen, and the illegal "query panel" sites where citizens' information was sold — demonstrated that such open services could be used to confirm and enrich leaked data. The shutdown is best read as one link in a chain of measures taken against this ecosystem.

The second factor is KVKK/GDPR compliance and accountability: an anonymous verification service where it was impossible to trace who was querying whom, and for what purpose, was incompatible with the data-processing principles of personal data protection law. Under the KPS model, by contrast, every institution is defined through a bilateral agreement, the services and data scope it may access are specified, and all queries are logged. The third factor is financial: as the free public service was closed, the same function was moved to KPS, where a participation fee is charged per query.

5. Impact on the Captive Portal / Hotspot Industry and the Law 5651 Dimension

Law No. 5651 ("On the Regulation of Publications Made on the Internet…") and the related regulations impose on those who provide mass internet access for commercial purposes (hotels, cafés, restaurants, shopping malls, etc.) an obligation to keep internal network traffic records (IP allocation logs, timestamped access records). The legislation does not explicitly mandate a specific identity verification method (T.C. ID number or SMS); the real expectation is that, in the event of a legal incident, it be possible to determine which user the traffic belongs to. T.C. ID verification was a method that strengthened this determination and — because it was free — had become the de facto standard.

The practical consequences of the shutdown were as follows: in portal setups that relied on T.C. ID verification, the verification step stopped working, and vendors had to release updates and notices for their products. When verification cannot be performed, two risks arise: either the portal accepts fake/made-up T.C. ID entries and the logs kept fail to match a real person (defeating the purpose of Law No. 5651), or the business removes verification altogether and simply opens up access. For this reason, the industry migrated en masse to SMS OTP, which can effectively identify the user — since a GSM number, through its subscription record, already makes it possible to reach the person.

The developer ecosystem was affected too: open-source libraries and REST API projects that wrapped the NVİ service were archived with "DISCONTINUED" notices, and some SaaS platforms that generated contracts using T.C. ID verification suspended those features.

6. The New Official Route: The Identity Sharing System (KPS)

For organizations that wish to continue verifying identities, the official channel is now KPS. KPS is the system that enables the population records held in MERNIS to be shared online, around the clock and in an auditable manner, with public institutions and other legal entities. The access model works like this: the organization applies via kpsbasvuru.nvi.gov.tr; a bilateral agreement/protocol is signed between NVİ and the applying institution defining which services and data scope it may access; and access is carried out over the KPSv2 web services, under the institution's identity and with logging.

On the pricing side, the "Communiqué on the Procedures and Principles Regarding the Identity Sharing System Participation Fee," published in the Official Gazette on 27 June 2020, set the per-query participation fee at 3 kuruş and provided for it to be increased each year at the revaluation rate; with the revaluation increases, this amount had reached roughly 0.23 TL per query by 2025 (a figure reported by industry sources). While public institutions covered by Law No. 5018 (more than 2,000 institutions) use the system free of charge, private-law legal entities use it by paying the participation fee. In addition, the press has reported that the participation fee is occasionally subject to high-rate updates (e.g. news of a 50% increase).

The practical reality specific to captive portals is this: the KPS application, the protocol process and the technical integration (KPSv2, including the serial-number field) are not something a small café or hotel can carry out on its own — and moreover, as explained in the section below, the vast majority of private-sector companies do not even have the right to access KPS in the first place.

7. Who Can Use KPS? Can Companies Access KPS for Hotspot Use?

The answer to this question is clear in the legislation and is decisive for businesses that operate captive portals: KPS is not a system open to every company that applies.

7.1. The framework set by the legislation

Who may benefit from KPS is determined by an exhaustive enumeration (numerus clausus) in Article 45 of Law No. 5490 on Population Services. As also confirmed on NVİ's official FAQ page, those who may apply to KPS are:

  1. Public institutions and organizations (those covered by Law No. 5018 use the system free of charge),
  2. Legal entities that provide public services (e.g. electricity/water/natural gas distribution companies and other bodies operating under a public-service concession),
  3. Banks and companies established for the purpose of sharing information with the Risk Center,
  4. Insurance and pension companies,
  5. Financial leasing and financing companies,
  6. Capital market intermediary institutions and portfolio management companies,
  7. Payment service providers.

Applications are made entirely electronically (with an e-signature) via kpsbasvuru.nvi.gov.tr and are evaluated by the Data Sharing Board; the Board determines which institution may access which service, and with what data scope. A commitment/bilateral agreement covering the purpose, legal basis, powers and responsibilities, and security measures is signed between the organization granted access and NVİ.

7.2. Can an ordinary company use KPS for hotspot? — No

An ordinary private company operating in any sector (a hotel, café, shopping mall, factory, IT firm, restaurant chain, etc.) falls into none of the categories above, and therefore cannot apply to KPS directly and cannot use KPS for guest Wi-Fi (hotspot) identity verification. Private-sector businesses other than the finance/insurance institutions enumerated in the law fall outside the scope of the service.

Beyond this, there is a second obstacle: purpose limitation. Under Article 45/3 of Law No. 5490, organizations that obtain data from KPS may not use this information "for any purpose other than performing the defined services." In other words, even a bank that has KPS access may use that access only for the banking transactions defined in its commitment; running a KPS query on the guest Wi-Fi portal in its branches would be use outside the intended purpose and would trigger sanctions, including revocation of access.

7.3. Who can (legitimately) use KPS in a hotspot scenario?

In practice, those who can sustain a T.C. ID-verified captive portal via KPS are essentially on the public side: municipalities (public city-wide Wi-Fi), universities, public hospitals, ministries and other public institutions — these are already the natural users of KPS and, to the extent they can add this usage purpose to their commitments, they can continue to verify. The "NVİ KPSv2" verification options that hotspot/firewall vendors add to their products also work only if the customer has its own KPS access and institutional credentials; a vendor offering bulk KPS verification to all its customers through its own account is not a legally compliant model (data must be queried in the name of the receiving institution and within the scope of that institution's commitment).

The upshot: for private-sector businesses that operate captive portals, there is in practice no official path back to T.C. ID verification; for these businesses, the legally safe route is SMS OTP and similar methods that make the user identifiable through their GSM subscription.

8. Alternative Verification Methods for Captive Portals

The methods that can be applied in the field today, and how they weigh up, are as follows:

SMS OTP (one-time password): The new de facto standard. The user enters their GSM number and opens a session with the code sent by SMS. Identification through the GSM subscription is indirect but strong; foreign guests can also be covered (with their roaming numbers). The cost is a per-SMS charge, and it requires an agreement with a bulk SMS provider.

T.C. ID verification via KPSv2 (only for those with access rights): For organizations that have KPS registration and a bilateral agreement, T.C. ID verification can be sustained at a per-query fee. As explained in Section 7, this route is open only to public institutions, legal entities providing public services, and the finance/insurance institutions enumerated in the law; ordinary private companies cannot use this option.

Sponsored / email-confirmed access: The guest's access is opened with the approval of a "sponsor" employee within the organization or through email activation. Suitable for corporate guest networks; identification rests on the sponsor.

Hotel scenario — PMS integration: Verification by room number + surname. Since the hotel already legally obtains the guest's identity (through Law No. 1774 on Identity Notification and the KBS system), tying the Wi-Fi session to the stay record is a clean solution for both Law No. 5651 and KVKK.

Username/password, voucher/ticket codes: One-time codes issued at a registration desk upon presenting ID; used in congress, event and guesthouse scenarios.

Open access without verification: Although technically possible, it carries legal risk for commercial mass-use providers because the user cannot be identified in the event of an incident; it is not recommended.

A note from the KVKK perspective: although the T.C. ID number is not classified as special-category data, under the data-minimization principle it is an identifier that "should not be collected unless necessary"; the KVKK Authority has, by a principle decision, even restricted the taking of ID photocopies in the hospitality sector. From this angle, the switch to SMS OTP is, in the view of many experts, a more compliant practice than collecting T.C. ID numbers on guest Wi-Fi: it satisfies the identification purpose while preventing a pool of T.C. ID numbers from accumulating in the business's hands.

9. Assessment and Recommendations

The shutdown is not an isolated technical decision; it is a policy shift aimed at preventing the uncontrolled verification of personal data through state services in Türkiye. In the short term it has caused disruption and cost (SMS/KPS fees) in the hotspot industry, and in the medium term it has moved identity verification onto channels that are kept on record (KPS, e-Government).

For an organization that still operates or is setting up a T.C. ID-verified captive portal, the recommended roadmap is:

  1. Disable the NVİ public-service integration in your portal — the service no longer responds and cannot block fake entries.
  2. Switch to SMS OTP as your primary method, and enable a passport number + SMS flow for foreign guests.
  3. If the customer is a public institution or one of the entities enumerated in Article 45 of Law No. 5490, start the KPS application (kpsbasvuru.nvi.gov.tr) and configure your hotspot vendor's KPSv2 module with the institution's own access credentials — for private companies outside this scope, the KPS option is not available.
  4. Do not change your Law 5651 log signing and timestamping setup — what has changed is not the logging, only the pre-session identification method.
  5. On the KVKK side, update your disclosure notices to reflect the new method (processing of GSM numbers), and review your retention/destruction policy for your old T.C. ID records.

A Note for SignLogger Users

SignLogger's Hotspot Management / Captive Portal module offers, out of the box, verification methods that do not depend on the NVİ public service — SMS OTP, username/password, sponsor-approved form verification, and LDAP; the log-signing and timestamping arrangement under Law No. 5651 is unaffected by this transition. For setup steps, take a look at the Captive Portal User Guide.

10. Sources (Official Institutions)

Last updated: 01 August 2026

Questions about SignLogger?

Contact us