ORBIS.ID
You are on Anyone PUBorbis.id

ORBIS.ID · PROOF YOU CARRY

You are not a copy of your passport.

Every time someone needs to know one thing about you, you hand over everything. Your name, your face, your address, your date of birth — copied into a database you will never see, run by a company you will never meet. ORBIS.ID replaces the copy with a seal: proof of the one thing they asked, that anyone can check and nobody can forge.

Not run

the checks have not run in this browser yet

Checked in your browser, against the machine that serves it. No account. No key. No bill.

Verifying a conformance vector recorded from https://id.orbis.id/conformance/vectors on 2026-08-30. Recorded data, live verification — the maths ran here, just now.

They wanted a yes. You gave them a filing cabinet.

What happens today

You photograph your passport. Again. Someone needed to know one thing — that you are old enough, that you live where you say, that you work where you say. They now hold your name, your face, your address and your date of birth, forever, on a server you will never see. When it leaks, the loss is not theirs. It is yours, and it is permanent, because you cannot change your date of birth after a breach the way you change a password.

What happens with ORBIS

Someone who already knows the answer — your bank, your employer, your university, your city — signs it once. That signed answer lives on your phone, locked to the chip inside it. When somebody asks, you send the answer and nothing else. They can check it is real without asking anyone, without an account, and without learning a single thing you did not send.

36 million

Americans hit by identity fraud last year. $38 billion lost. Most of it starts with data someone else was storing about you.

Javelin · April 2026

$4.99M

the average cost of a data breach, up 12% in a single year.

IBM · July 2026

69 million

age checks performed in the UK in six months after one new law. Almost all of them asked people to upload ID to a stranger.

Ofcom · July 2026

And now it is becoming the law.

Age checks at the door of the internet. Digital identity written into statute. Voting, banking, medicine, the sale of a second-hand car — each one arriving with a duty to prove who you are, and a quiet assumption that proving means handing over the document.

None of those laws are wrong to want an answer. Every one of them is being built to take the whole file. That decision is being made right now, in parliaments, by people who were never shown a third option.

There is a third option, and it is not a loophole. The law says prove it. ORBIS says prove it without confessing. Billions of people are about to be enrolled in something over the next few years, once, and for a long time. It matters enormously which thing it is.

The arrow that is missing is the one that matters.

The three parties, and the connection that does not exist who vouched sends a signed answer to who holds it. who holds it shows it to who is asking. There is no connection from who is asking back to who vouched: it is drawn and struck through. who vouched who holds it who is asking never happens

Three roles, and they are never allowed to merge. Someone vouches. Someone holds. Someone checks. Collapse any two of them and you have rebuilt a login provider — a company that sits in the middle of your life and watches.

Look at what is not on this diagram. There is no arrow from the person asking back to the person who vouched. That is not a courtesy. It is the shape of the thing: your bank never learns which bar you walked into, because the bar never talks to your bank.

One row travels. Four stay.

They asked one question. Give them one answer.

The four rows that stayed behind are not being withheld out of politeness, and they are not sitting in the message greyed out. They were never put into it — and the signature still checks out without them. That is arithmetic, not policy. There is nothing here you have to trust anybody about, which is the only kind of privacy that survives a bad year.

Illustration · a credential, drawn

  • over_18 shared
  • member_name never sent
  • member_id never sent
  • member_since never sent
  • organization never sent

What the verifier received: 0 bytes of you.

From an organization to proof anyone can check.

Four moves. Nobody has to install a platform, sign a partnership, or join anything. The bank that already knows the answer signs it; the person carries it; the stranger checks it. That is the entire arrangement, and there is no fourth party in it.

  1. Set the organization up

    Its own verified name on the internet, a signing key it never has to handle, its brand on everything it hands out. Minutes, not quarters.

  2. Hand out proof

    The person scans a code and it lands in their wallet, built so that later they can share one fact from it without revealing the rest.

  3. Hold and control

    It lives on their phone, tied to that device. They decide what to show, and to whom, every single time.

  4. Check it anywhere

    Anyone can check four things: the signature is real, the organization behind it is trusted, this is the right holder, and it has not been withdrawn.

251 of 582 routes take no key. Ever.

curl -s https://id.orbis.id/openapi.json | jq '[.paths[][]["x-auth"]] | group_by(.) | map({(.[0]): length}) | add'

Measured from https://id.orbis.id/openapi.json on 2026-08-30. Run it and see if it still says that.

Checking is free forever, and not as a promotion we can end. There is no door on the checking path to charge you at — which is the same fact as there being no door to record you at. We could not build a log of who checked whom without first building a way to bill you for it, and we have not built either. The price and the privacy are one property with two names. Do not take that on faith: count the routes yourself.

Before you go any further.

This is a platform being built in the open, and the state of every piece of it is published. Not summarised — published, with the thing that proves it, including the pieces that do not work. Almost nobody in this industry prints the rows that say no. Those are the ones worth reading first.

  • LIVE Publishes deterministic vectors a third party can recompute offline to check their implementation against ours conformance-vectors
  • PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

8 of the 10 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • did-web-anchor
  • vc-issuance
  • selective-disclosure
  • hosted-verification
  • revocation
  • wallet-web
  • account-recovery
  • self-service-onboarding

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

For your whole life, identity has been something done to you. You are known about, copied, filed and breached, and you cannot change what leaks. This turns the pen around: a key born inside your own hardware is not a record of you, it is a thing you own. And proof without confession is the oldest right there is — to be believed without being exposed.

Do not trust us. Check us.