ORBIS.ID Open the walletWallet

For people

Your life, in your pocket. Not in their database.

Every time you open an account, start a job or rent a flat you hand over copies of your life and hope they are looked after. A proof replaces the copy: the other side gets the answer it asked for, and nobody gets a filing cabinet full of you.

Every promise on this page names an entry in the public capability register, and where an entry is not live the state is printed beside the claim rather than filed away somewhere else.

01

Prove one thing without revealing five

A doorman needs to know one fact: are you over 18. Today you hand over a document carrying your full name, exact date of birth, address, document number and photograph — and any of it can be copied.

A credential answers only the question that was asked. Over 18 without your birthday. Resident without your street. Employed without your salary. Insured without your policy number.

Selective disclosure of an age credentialA driving licence reveals nine fields today. A verifiable credential reveals only that the person is over eighteen.TODAY — SHOW THE DOCUMENTDriving licence handed over× Full legal name× Exact date of birth× Home address× Document number× Photograph× Licence categories, issue & expiry datesAll of it copyable. Most of it irrelevant.the question was“Are you 18+?”one bit of informationWITH ORBIS.ID — ANSWER THE QUESTIONWhat actually leaves your phoneover 18 · yes…and a proof that the answer came from acredential a trusted authority sealed, thathasn’t been altered or revoked.Name, birthday, address: never transmitted.Same mechanic everywhere — prove you earn enough without showing your salary · prove you’re licensed without showing your address · prove residency without showing the lease.
Selective disclosure of an age credential

What is real here

  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.

02

Stop the copies

Your passport scan sits on servers you will never audit, and every copy is a target. When one of those companies is breached it is you, not them, who spends the next stretch of your life proving you are still yourself.

The other side checks the seal and gets its answer. Nothing is filed away afterwards, because the answer was checked rather than collected.

Comparison of document copying versus proof presentationAbove: a person's document is copied to four organisations, each storing a copy, creating breach targets. Below: the person's wallet answers a yes-or-no question and no copy is stored.TODAY — THE COPY TRAVELSYoupassport · payslip · billsend copiesBankstores a copyLandlordstores a copyInsurerstores a copyTelecomstores a copyFour breach targetsAny one leak exposes you —and you do the recovering.WITH ORBIS.ID — ONLY THE ANSWER TRAVELSYour walletsealed proofs, onyour device only“over 18?” → yesBankchecks the sealkeeps nothingLandlordchecks the sealkeeps nothingInsurerchecks the sealkeeps nothingNothing to stealNo pot of data was everassembled to breach.The copy of your life stops travelling. Only the answer does.That single change removes the honeypot, the fraud, the friction and the cost — all at once.
Comparison of document copying versus proof presentation

What is real here

  • Live A holder can prove a single claim — over 18, licensed, employed — without revealing the rest of the credential.
  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.

03

Anyone can check it, so it is worth carrying

A proof is only useful if the person in front of you can check it without joining anything. Checking an ORBIS proof needs no ORBIS account, no key, and no payment, and the library that does the checking is public and installable by anyone.

Because the check runs against published open standards rather than an ORBIS lookup, your degree survives the university's next IT migration and your record travels with you across a border instead of resetting you to zero.

The issuer, holder and verifier trust triangleAn issuer signs a credential to a holder, the holder presents a proof to a verifier, and the verifier checks the issuer's key and trust status without contacting the issuer directly.ISSUERbank · university · employer · city“this is true, and I’ll stake my key on it”HOLDER — YOUthe credential lives here, on your deviceyou choose if, when and how muchto reveal — every single timeVERIFIERlandlord · airline · hospital · marketplacegets an answer, not a document —and keeps no copy1 · issues a sealed credential2 · presents a minimal proofsingle-use · scoped · revocable3 · checks the seal againstthe issuer’s public key and thetrust registry — no contact withthe issuer, no notification to themThe missing line is the point: no arrow runs from verifier to issuer carrying your name. That is what makes this private rather than merely digital.
The issuer, holder and verifier trust triangle

What is real here

  • Live Anyone can verify an ORBIS credential without registering, paying, or asking permission.
  • Live A zero-dependency library that checks ORBIS credentials in Node or a browser, and performs no network calls of its own.
  • Live Sixteen public test vectors let anyone prove their verifier accepts what it should and refuses what it should not.
  • Live Issue credentials over OID4VCI as SD-JWT VC — the same wire any standards-compliant wallet already speaks.

04

And it can be taken back

A proof is not a document that escapes you the moment you show it. Whoever issued it can withdraw it, and the next check sees that it is no longer valid — without the issuer learning who checked, or where.

How revocation works privatelyThe issuer publishes a compressed status list; the verifier downloads the whole list and checks one bit, so the issuer never learns which credential was checked.Issuer withdrawsemployee leaves · licence lapses ·device sold · card reported lostOne bit flips in a public status list…131,072 positions, compressed to a few kilobytesThe list says nothing about who anyone is — it’s just bits.Verifier downloads the whole list…and checks one position locally. Because it never asksabout a specific credential, the issuer learns nothing.The old way: call the issuer“Is credential no. 4,182 still valid?” tells the issuer exactlywhere and when you are proving things. That’s a trackingsystem wearing a security badge.The ORBIS way: check a bitRevocation is immediate on the next check, works atnational scale, and produces no record of who verifiedwhat, where, or when.
How revocation works privately

What is real here

  • Live A revoked credential stops verifying, without the issuer learning where or when it was checked.

05

The wallet you keep them in

The wallet runs in a browser. The key that makes the proofs yours is created on your own device and is never transmitted.

A native app in each app store, using the phone's own biometrics and secure element, is named here so its state is visible rather than assumed.

What is real here

  • Live Holders can receive, hold and present credentials from a browser, with keys created on their own device.
  • Planned A native app in each app store, with platform biometrics and secure-element key storage. Planned — the wallet is web-only today.

06

If you lose your phone

This is the part most identity products go quiet about, so: the key is created on your device and never leaves it. That is what makes the custody promise real, and it is also why losing the device today means losing access to what it held. One wallet, one device.

Restoring your credentials onto a replacement device is named in the register with its state, and the state is not "shipped". Do not plan around a recovery path that does not exist yet.

What is real here

07

Your things, and their history

The idea: ownership of your car, your appliances and your devices held as proof you can transfer when you sell, delegate when you lend, and keep when the manufacturer switches off its cloud.

It is on this page so it can be discussed in the open. Read the state printed with it before treating any of it as available.

Individual, organization and city rings of device ownershipNested rings showing individuals inside organizations inside cities, all served by the same five credential primitives.RING 3 · CITY / PUBLIC BODYOwns infrastructure. Needs data it doesn’t own. Must justify every sensor.RING 2 · ORGANIZATIONOwns fleets and buildings. Delegates to staff, contractors, agents. Liable.RING 1 · INDIVIDUAL / HOUSEHOLDOwns things. Generates the data the other two rings want.RING 0 · THE DEVICE OR AGENTacts only under authority delegated inward-out —scoped, expiring, revocable, and verifiable by anyoneOne credential grammar, three marketsP1 · Identity bindingthis identifier is this physical thing — attestation wrapped, not replacedP2 · Ownershipthis person, company or public body owns it, from this dateP3 · Delegationthis holder may do these things, until this time, on the owner’s authorityP4 · Data authorizationthis recipient may receive this scope, for this purpose, revocablyP5 · Lifecycle eventtransfer, repair, update, incident, disposal — appended, never overwrittenWhy the nesting mattersA city can’t get consented citizen data unless individuals hold wallets.An individual’s data has no buyer until organizations are obliged to want it.
Individual, organization and city rings of device ownership

What is real here

08

What this page does not claim

The content master proposed four more promises for this page. None of them has an entry in the capability register, so none of them is made here: a health record held encrypted on your device and shared by scoped, time-boxed link; bills that arrive cryptographically signed by a biller proven at the moment of delivery; calls and messages bound to verified identity; and a share of the value when data you produced is licensed.

The member-owned economics described elsewhere are a designed structure, not an operating one. Distributions, token mechanics and fund participation are subject to formation, regulatory approval and jurisdiction-specific legal confirmation, and are not offered or available today.

Core-service pricing, a distribution formula weighted toward those with least, and app-store availability are all absent for the same reason: no register entry, no claim.

Straight answers

Questions people actually ask.

What happens if I lose my phone?

Today, you lose access to the credentials that device held. There is no recovery path in the wallet or the platform, and this site will not describe one until there is. The register entry for recovery carries its state and the evidence behind it.

How do I know what is actually built and what is a plan?

Every capability this site claims names an entry in the public capability register. The register carries four states — live, partial, in build, planned — plus how each state was established and the date it was last checked. Where a claim is not live, the state is printed next to the claim, not filed away on another page.

Is this an offer to invest, or a promise of income?

No. Nothing here is an offer of securities or investment advice, and the economic and governance structures are a designed framework subject to formation, regulatory approval and jurisdiction-specific legal confirmation.