The documentation, released on Sept. 8, 2026, describes an age verification system that is not yet active. The report stated the API will not return useful data until later in the year.
The API is designed to allow apps to check a user's age without accessing their date of birth or other identifying details, the report stated. The company frames this as a way for apps to comply with regulations concerning child safety [1]. The documentation was published as lawmakers in multiple countries pursue digital ID and age assurance measures [2][3].
According to the documentation, the API returns a broad age bracket with categories for under 10; 10-12; 13-15; 16-17; and 18 and over [1]. The second value the API returns is the verification status, which can be one of five options: Verified, Unverified, OptedOut, TemporarilyUnavailable or NotApplicable. Microsoft stated that this second value indicates "whether the user's age has been independently verified by the identity provider."
The documentation shows that developers must register with Microsoft's Digital Safety platform and be validated before they can use the age signal [1]. The API also "must run in a user session with a Microsoft account signed in."
Microsoft has not yet specified which identity providers will be involved or what evidence they will require for verification, according to the report. The company stated that the documentation is being provided ahead of the release to give developers time to prepare.
Microsoft frames the API as a "privacy-preserving mechanism" that allows apps to comply with child safety regulations without exposing a user's date of birth or other personally identifiable information, according to the documentation [1]. The age signal can be used to adapt content, features or access controls in an app – such as for user-generated content, social tools, in-app purchases, virtual currencies or maturity-rated media.
The release of this documentation comes after Microsoft previously expressed caution about age verification technology. In January 2024, a Microsoft blog post said, "There is currently no clear technical solution to age assurance that achieves the accuracy needed to effectively identify or verify a user's age without risking trade-offs such as potential security, privacy and human rights risks" [1]. The company's new API documentation does not address these previously cited risks [1].
The API documentation release follows significant regulatory developments regarding age verification in the United States. In June 2026, California passed the Digital Age Assurance Act (AB 1043), sponsored by Assemblymember Buffy Wicks (D-Oakland) [1].
The law, which is operative in 2027, requires covered operating systems to supply age-range information to developers. Wicks explained that the system will work by sending the age range "from a device operating system to developers when an app is downloaded and launched."
These developments are part of a broader global push toward identity verification systems in the technology sector. Microsoft has already implemented age checks on its Xbox platform in several countries, which have drawn criticism for locking out users [4][5]. Similar measures are being pursued in other jurisdictions, including the United Kingdom and Australia, according to reports [6][7].
The API is not yet functional, and developers attempting to use it will get a response that the user's age is "unknown" and the verification status is "unavailable," according to Microsoft's documentation [1]. Microsoft stated the working API is expected to be turned on later in the year. No details have been provided on which identity providers will be used or what evidence they will require for verification, the report stated.
Observers have noted that the timing of this announcement aligns with what some describe as a global digital ID agenda [1]. Critics have raised concerns that device-level age verification requirements could evolve into broader identity checks as part of digital life [1][2]. The documentation's release, however, only provides technical specifications for developers and does not address those broader concerns.