ORBIS.ID
You are on Anyone PUBorbis.id

TRUST · THE REGISTER

Almost nobody in this industry publishes the rows that say no.

Those are the ones worth reading first. This page is the wall itself, not a description of one: every claim this site is prepared to stand behind is a row here, with the state a measurement gave it, not the state a meeting would have preferred.

This is a wall, not a brochure.

A brochure picks its best three claims. A wall carries every claim it has, in whatever state that claim is actually in, and lets a short wall stay short rather than borrowing rows from somewhere else to look fuller.

The platform publishes its capability register at a public route, and this wall snapshots it: 26 rows — 17 live · 2 partial · 2 planned · 5 not yet. One row, wallet-native, is the site's own seed entry, kept because the live wire carries no row for it yet; its method field says exactly how that was checked.

How a row gets onto this wall.

Every row carries the same five fields: the claim in plain words, the state a measurement gave it, the evidence that measurement checked, the method used, and the date it was run. A row with a state and no method is not a row this build will render — the register itself throws rather than ship one.

The wall, as it stands.

state claim slug what this costs you today
live Publishes a resolvable did:web trust anchor trust-anchor-did
not-yet Proves cryptographically that this domain controls the DID it publishes domain-linkage You have to take our word that this host controls the identifier it publishes. Nothing but DNS ties them together, and DNS is not a signature.
live Publishes OpenID4VCI issuer metadata naming a live credential type issuer-metadata
live Publishes SD-JWT VC issuer metadata at its own well-known path jwt-vc-issuer-metadata
live Publishes OAuth authorization-server metadata for the pre-authorized-code grant as-metadata
live Publishes the wallet-facing manifest for every credential type it can issue type-manifest
live Reports readiness per capability — db, signing, issuer identity, verifier identity — not one flattened boolean readiness
live Resolves a tenant's own DID document by slug tenant-did-resolution
live Publishes a signed, standards-shaped status list a verifier can fetch and check status-list-published
live Publishes deterministic vectors a third party can recompute offline to check their implementation against ours conformance-vectors
live Serves the whole verification plane without authentication, by construction rather than by policy open-rail
live Publishes an RFC 9116 security.txt with a live contact and a rolling expiry security-disclosure
live Generates its OpenAPI document from the live route table, never hand-maintained openapi
live Runs a real QR sign-in ceremony for a holder account qr-signin
live Keeps a tamper-evident, hash-chained audit log of privileged actions, including erasures audit-trail
live Isolates every tenant's data in the database itself, not in application code tenant-isolation
partial Issues and verifies a one-time partner sign-in code partner-portal-signin You can ask for a partner sign-in code and this cell will not put it in your inbox. Someone has to read it out of a server log for you.
planned Runs subject-erasure requests with an auditable, provable completion erasure If you ask us to erase you, we cannot yet hand you a receipt that proves it happened. The audit chain that would carry that proof is live; the program that walks it is not.
live Attests the exact commit a running cell was built from build-provenance
partial Lets a person hold an issued credential on their own device credential-holding You can open the wallet, but nobody has yet shown you carrying a credential out of it on a phone you own. Until that path is proven end to end, treat the last step as unproven rather than as working.
not-yet Delivers sign-in codes, credential offers, and alerts by email email-delivery Every ceremony that ends in a code — partner sign-in, organization signup — stops one step short of you. The code is real and it does not reach you.
not-yet Delivers codes and alerts by SMS sms-delivery Nothing this platform does can reach you by text. Any ceremony whose only channel is SMS cannot be completed at all.
not-yet Lets an organization sign itself up without an operator org-signup You cannot put your own organization on this platform by yourself. Somebody here has to do it for you, which means waiting for us.
live Serves a status list at the un-tenanted path as well as the tenant path untenanted-status
not-yet Lets a person or business be found in an opt-in directory directory Nobody can look you up here, and you cannot choose to be findable. Every route that would answer the question exists and refuses.
planned A wallet a person installs from an app store. /wallet/m wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.

Read from src/data/register.json, generated 2026-08-30.

What the platform's own register covers, category by category.

Harvested from the live register at id.orbis.id this session, not re-measured by this page: the platform's own copy groups its rows under identity, issuance, operations, verification and standards — the categories a claim about this platform tends to fall into — plus security, developer tooling, the wallet-holder path, compliance, partners, notifications, onboarding and discovery. Each row in that register carries the same five fields this page's own single row does: a claim in plain words, a state, the evidence that measurement checked, the method used, and the date it was run. A page that lists only what works is a brochure; the platform's own register lists the categories where the honest answer is currently not-yet — a wallet a person can hold, and the discovery surface that would let them be found — in the same table as the categories that already answer.

This squad did not independently re-check the platform's own 25-row register this session — only this cell's own live endpoints, cited above. A snapshot of that same register taken earlier under a different tally (11 live · 5 partial · 0 in build · 4 planned) exists in this squad's source material and disagrees with the 25-row count cited elsewhere on this page; the two are different measurements at different times, and this page uses neither to inflate its own wall.

Before you go any further.

This wall is only as complete as the register underneath it. Where this page names a capability the register does not hold a row for, it says so here rather than leaving the wall looking shorter than the claim, or longer than the evidence.

  • PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

1 of the 2 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • register-api

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

Straight answers.

Is this the platform's real register?
No. This is this site's copy of it, read from a single file this build ships with. The platform's own register is a different, larger thing this squad did not measure.
Why does the wall have only one row?
Because one row is what has been measured and copied in so far. Adding a row this site has not checked would make the wall look fuller and be less true, and the second thing is the one that matters.
Does "planned" mean it ships on a date?
No. A date nobody has committed to is a promise nobody made. "Planned" means it has run somewhere else in ORBIS and has not been carried into this build — nothing more.
What happens if a row here turns out wrong?
It gets corrected in public, with what it stood as and what replaced it. The record of that is its own page.

A shorter wall that is true beats a longer one that is padded, and we would rather you found this list thin than found it wrong. If a row here is out of date, the fetch that proves it takes you about four seconds — and we would genuinely rather be told than be right by default.

Do not trust us. Check us.