Your identity
You sign in with Google, Apple ID or a crypto wallet. From that account, the wallet derives an identity: a key pair and the decentralized identifier (DID) built from it. The DID is how apps and issuers refer to you. The private key never leaves your control.Zero-knowledge proofs
When an app asks you to prove something, the wallet doesn’t send the credential. It builds a zero-knowledge proof that the credential satisfies the app’s request, and sends only that. The app can check the proof, but learns nothing else about the credential or the data behind it. Proofs are verified on-chain or off-chain, depending on the request. Where the proof is generated depends on the wallet:
In both cases, no personal data or cryptographic material leaves your device while the proof is generated.
Credential storage
Every credential is encrypted and stored in cloud storage, which acts as a backup and lets you use the same credentials on several devices. When you sign in, the wallet derives your storage keys from your account.- Signature scheme: ed25519
- Encryption: AES-256-GCM
- Access: only the person holding the storage keys can decrypt the credentials
Sync across devices
Sign in with the same account (Google, Apple ID or crypto wallet) on the web and on your phone, and every credential you’ve claimed on one is available on the other. You never need to claim a credential twice.Related
- Credentials: what each credential proves.
- How Verification Works: what happens when an app asks for a proof.