ORBIS.ID Open the walletWallet

For business

Verify more. Hold less. Be liable for almost none of it.

A credential your customer already holds can be checked properly, every time, by your own code. The data you never stored is data you can never lose, never have to defend, and never have to report.

Every promise on this page names an entry in the public capability register, and where an entry is not live the state is printed beside the claim rather than filed away somewhere else.

01

Accept a check that was already done properly

The same identity check is repeated from scratch at every bank, insurer, telecom and landlord, and each repetition creates another copy to defend.

A credential issued over open standards can be presented to you and checked on its own merits — issuer, integrity, expiry and status — with the holder disclosing only the fields your check actually needs.

The credential lifecycle in four stagesIssue, hold, prove and revoke, showing what each party learns and does not learn at each stage.1IssueA bank, university or authority seals a statement about youIssuer signs• what is true about you• when it expires• a signature that breaks if altered2HoldIt lands in your wallet — not a company’s serverYou keep it• keys in your device’s secure chip• unlocked by face or fingerprint• works offline3ProveAnswer the question asked — and only thatVerifier checks• seal genuine & unaltered• issuer trusted · not expired• single-use, can’t be replayed4RevokeWithdraw it, and every future check sees thatEither side can end it• issuer withdraws the credential• you revoke a verifier’s access• effective on the next checkWhat never happensThe issuer is never told where you used it. The verifier never gets a copy to keep. No profile is built as a side effect of proving something true.
The credential lifecycle in four stages

What is real here

  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.

02

A credential cannot be photoshopped

A document photo is a picture of a claim. A credential is the claim itself, signed, with a published key you can resolve yourself.

A withdrawn credential stops verifying on the next check, and the issuer does not learn that you were the one checking.

The five parts of a verifiable credentialIssuer, subject, claims, validity window and signature, with the technical term for each.A sealed statementWho said itthe issuer’s identifier — a key nobody else can sign withissuer / DIDWho it’s aboutbound to you, so it can’t be lifted and reused by someone elsesubjectWhat it sayseach fact separately disclosable — share one, keep the restclaimsHow long it’s good forvalid-from and expiry, plus a pointer for withdrawalvalidity + statusThe seal — change one character and it breakssignatureWhat the verifier checks, every time1 · the signature is mathematically valid2 · nothing in the credential has been altered3 · the issuer is on the trust registry for this credential type4 · it is inside its validity window5 · it has not been revoked6 · the presenter is the person it was issued to
The five parts of a verifiable credential

What is real here

  • Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
  • Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.

03

Minimisation stops being a policy and becomes an architecture

The cheapest way to survive a breach is not to hold the data. When a holder proves a single fact rather than surrendering a document, the record that would have leaked was never assembled.

Selective disclosure of an age credentialA driving licence reveals nine fields today. A verifiable credential reveals only that the person is over eighteen.TODAY — SHOW THE DOCUMENTDriving licence handed over× Full legal name× Exact date of birth× Home address× Document number× Photograph× Licence categories, issue & expiry datesAll of it copyable. Most of it irrelevant.the question was“Are you 18+?”one bit of informationWITH ORBIS.ID — ANSWER THE QUESTIONWhat actually leaves your phoneover 18 · yes…and a proof that the answer came from acredential a trusted authority sealed, thathasn’t been altered or revoked.Name, birthday, address: never transmitted.Same mechanic everywhere — prove you earn enough without showing your salary · prove you’re licensed without showing your address · prove residency without showing the lease.
Selective disclosure of an age credential

What is real here

  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.

04

Workforce and contractor authority that expires

Right-to-work, qualifications, professional licences and contractor scope can each be issued as a credential with an expiry, so access ends when the engagement does rather than when someone remembers.

If it ends early, it is withdrawn and the next check sees it.

What is real here

  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.
  • Live A revoked credential stops verifying, without the issuer learning where or when it was checked.
  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.

05

Check it yourself, in your own process

A published library performs the whole validation chain in your own runtime, with no network call back to ORBIS, so an outage here is not an outage in your onboarding.

A public set of conformance vectors lets you prove your own verifier accepts what it should and refuses what it should not — including the failures, which is the half most test suites skip.

Credential events can be delivered to you as signed webhooks with retries and a dead-letter queue.

The issuer, holder and verifier trust triangleAn issuer signs a credential to a holder, the holder presents a proof to a verifier, and the verifier checks the issuer's key and trust status without contacting the issuer directly.ISSUERbank · university · employer · city“this is true, and I’ll stake my key on it”HOLDER — YOUthe credential lives here, on your deviceyou choose if, when and how muchto reveal — every single timeVERIFIERlandlord · airline · hospital · marketplacegets an answer, not a document —and keeps no copy1 · issues a sealed credential2 · presents a minimal proofsingle-use · scoped · revocable3 · checks the seal againstthe issuer’s public key and thetrust registry — no contact withthe issuer, no notification to themThe missing line is the point: no arrow runs from verifier to issuer carrying your name. That is what makes this private rather than merely digital.
The issuer, holder and verifier trust triangle

What is real here

  • Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
  • Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.
  • Live Subscribe to credential events over HMAC-signed webhooks, with retries and a dead-letter queue.
  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.

06

Getting an integration to production

Two parts of the partner path are not finished, and the states printed with this section are the whole truth about them.

The first is the scored exercise an integration passes before go-live. The second is minting and rotating your own API keys inside limits an operator granted you — until that lands, every key is issued by an ORBIS operator, so plan for a human in that loop.

What is real here

07

How the platform underneath is operated

Signing keys are moving to a hardware-backed vault, issuer by issuer, with the current count printed in the register rather than rounded up in prose.

Moving or rotating a signing key is composed by one operator and approved by another, and the whole ceremony is recorded. A sole-operator override exists for small teams; it requires a typed confirmation, writes its own audit event, and marks the record permanently.

Errors, unresponsiveness and degraded response times raise an alert. No service-level agreement is offered and no uptime figure is published — alerting is not an SLA and this site will not blur the two.

The deployment reports the exact commit it is running, so it can be compared against source.

What is real here

  • Partial Issuer signing keys live in Azure Key Vault, and the platform signs by calling the vault rather than holding the key. Partial — two of fifteen issuers today.
  • Live Moving or rotating a signing key is composed by one operator and approved by another, with the whole ceremony recorded.
  • Live Server errors, an unresponsive service and degraded response times raise an alert.
  • Partial The deployment reports the exact commit it is running so it can be compared against the source. Partial — commit reported; signed attestation unavailable.

08

Machines and agents

The idea: delegate bounded authority to a device or an autonomous agent, with a scope, an expiry, and a withdrawal anyone can verify.

There is no device layer in the platform today. The state is printed with this section; read it before it reaches a roadmap slide.

What is real here

09

What this page does not claim

The content master proposed several commercial promises this register cannot support, so they are absent: consent as a signed, revocable, auditable object; supplier and product-passport assurance checked against a named trust registry; and a "Sign in with ORBIS" flow. There is one published SDK — the verifier — not a family of them.

No figure is given for drop-off, cost per verified customer, fraud losses, or onboarding time. The master proposed those numbers without a source or a date, which is the one thing that disqualifies a number from appearing at all.

No compliance certification is claimed anywhere on this site. Aligned with is not certified under, and the difference is not decorative.

Straight answers

Questions people actually ask.

Why would we accept a credential instead of collecting the document?

Because holding the document is the liability. The insight you wanted survives the check; the record you would have had to store, control, audit, insure and eventually disclose does not.

What is not production-grade yet?

The capability register answers this directly, with four states and the evidence behind each. It is the same register the engineers work from, updated when something changes state in either direction — not a roadmap written for buyers.

Do you hold a certification we can rely on for our own audit?

No certification is claimed on this site. What is offered instead is checkable: public conformance vectors, an installable verifier, and a deployment that reports the commit it is running.