ORBIS.ID
You are on Anyone PUBorbis.id

ORBIS.ID · VERIFY

Check anything. No account, no key, no bill.

Someone has handed you a proof. You want to know three things: that it is real, that a real organization stands behind it, and that it still counts today. Press the button. The answer comes back from your own browser — nothing is sent anywhere, nobody is asked for permission, and no one, including us, learns that you looked.

Not run

the checks have not run in this browser yet

This is the ceremony, not a picture of one. The maths ran on your device a moment ago, and the controls below will run it again on a proof that is meant to fail.

Verifying a conformance vector recorded from https://id.orbis.id/conformance/vectors on 2026-08-30. Recorded data, live verification — the maths ran here, just now.

This page is the checking itself. Everything else under Verify explains what you just watched, or what it costs.

What your browser just did.

Five things, in order, each of which can fail on its own. The strip under the seal names all five in plain words and prints the result of each as a word, not as a colour — so a reader who cannot see the marks still gets the whole answer.

They are not five opinions. Each one is a piece of arithmetic over bytes the organization published itself: its signing key, its status list, the digests it signed. None of them asks anybody’s permission, and none of them can be answered with a yes by being polite.

A failure is not a crash. When something does not hold, the strip names the link that broke and says why in the reader’s language. A checker that returns a confident yes when it is confused is worse than one that says it could not tell.

Try to break it. That is what the second button is for.

The conformance set carries proofs that are supposed to fail, and the seal will run them on request: a credential whose organization has withdrawn it, one with a claim spliced in that the organization never signed, and one whose disclosed value was edited after signing. Each one exists because a plausible implementation gets it wrong.

An incomplete seal is a legitimate result and it is drawn as carefully as a complete one. The ring stops where the checking stopped, and the arc that did not close stays open.

251 of 582 routes take no key. Ever.

curl -s https://id.orbis.id/openapi.json | jq '[.paths[][]["x-auth"]] | group_by(.) | map({(.[0]): length}) | add'

Measured from https://id.orbis.id/openapi.json on 2026-08-30. Run it and see if it still says that.

Checking is free forever, and not as a promotion. There is no authenticated seam on the verification path to charge you at — which means there is also nowhere to build a record of where you verified. The privacy property and the price come from the same fact. Count the routes yourself.

The same proofs, without this page.

Nothing here is a demonstration built for the website. The proofs the seal runs are published by the machine that serves them, and you can pull them down and run them through your own verifier, in your own language, on your own machine.

curl -s https://id.orbis.id/conformance/vectors | jq '.vectors[].id'

Served from https://id.orbis.id/conformance/vectors — reached on 2026-08-30.

Before you rely on this.

Checking is the part of this platform that works best, and it is still worth reading the rows before you build on it. Every capability this page leans on is listed here with its real state and the thing that proves it — including the ones that are not there yet.

  • LIVE Publishes deterministic vectors a third party can recompute offline to check their implementation against ours conformance-vectors

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

4 of the 5 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • hosted-verification
  • revocation
  • selective-disclosure
  • did-web-anchor

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

Straight answers.

Do I need an account to check something?
No. There is no sign-in on this page and no key to obtain. The checking happens in the browser you are reading this in, against data the browser already has.
Do you find out what I checked?
The verification path carries no authentication, so there is nothing on it to attach a record of you to. That is a property of the shape, not a promise about our conduct — and it is the same fact that makes the checking free.
Can I check a proof from an organization that has never heard of ORBIS?
Yes, if it was issued on the same open rails. What the checking reads is the organization’s own published key and its own published status list. Neither of them lives here.
Does the checking phone the organization that vouched?
No. It reads what that organization published, the way a browser reads any page. The organization is never told who read it, which is why it never learns where its credential was used.
Is this the same code you tell developers to build against?
It is the estate’s own verifier, running here with no network access. An earlier bespoke version of it accepted a forged claim; it was deleted rather than patched, and the proven one took its place. Point your own verifier at the same vectors and judge it yourself.

Do not trust us. Check us.