ORBIS.ID
You are on Anyone PUBorbis.id

ORBIS.ID · VERIFY · AGE

They are over eighteen. That is everything you learn.

An age gate asks one question and takes a document that answers a hundred. The name, the face, the address, the exact date — all of it copied to a company that only ever needed a yes. There is another way to answer, and it has been sitting in the standards for years: send the yes.

One page, one idea: the birthdate is not hidden from you. It is not there.

You already did this once this year.

What happens today

A site asks whether you are old enough. You photograph a passport or a driving licence, upload it to a company whose name you had never read until that moment, and hold your face up to the camera. They now have your document, your face and your exact date of birth, in a place you cannot see, kept for a period you were not told. You needed to answer one question. You handed over the file.

What happens with ORBIS

Someone who already knows — the authority that issued the document, your bank, your university — signs the single fact once. It sits on your phone, locked to the chip inside it. The site asks, you approve, and one row leaves: over eighteen, yes. The site can check that row is genuine without asking anybody, and there is nothing else in the message to keep.

The birthdate is not hidden. It is not there.

This is the sentence that does the work, and it is worth being pedantic about. The four rows below are not greyed out, not encrypted, not withheld pending a warrant. They were never put into the message, and the signature still holds without them. That is arithmetic, not policy — there is nobody to trust about it and nothing to audit.

Illustration · a credential, drawn

  • over_18 shared
  • date_of_birth never sent
  • full_name never sent
  • document_number never sent
  • photograph never sent

What the age gate received: 0 bytes of you.

An illustration of a credential of this shape, not a live one.

The scale of what is being collected instead.

One law, one country, six months. Almost every one of those checks asked a person to hand a document to a company they had never heard of, and the documents are still sitting wherever they landed.

69 million

age checks performed in the UK in six months after one new law. Almost all of them asked people to upload ID to a stranger.

Ofcom · July 2026

What the checking side actually holds afterwards.

A yes, the challenge it generated for that one request, and the fact that the signature over both of them held. It cannot re-use the answer for a different request, because the challenge it was signed against was single-use — which also means a captured message is worthless to anyone who replays it.

That is the whole record. It is small enough to keep honestly and useless enough to leak harmlessly, and those two properties are the same property.

Before you put this in front of customers.

An age check on these rails needs a wallet to hold the credential and a checker to read it. One of those halves is further along than the other, and the rows say which.

  • LIVE Publishes deterministic vectors a third party can recompute offline to check their implementation against ours conformance-vectors
  • PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

3 of the 5 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • selective-disclosure
  • hosted-verification
  • wallet-web

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

Straight answers.

Can I get their date of birth later if I need it?
No. Not from us, and not from the proof. It was never in what you received, so there is nothing to retrieve, subpoena or leak. If your obligations genuinely require holding a birthdate, this is the wrong mechanism and you should say so out loud rather than collect one by accident.
How do I know the person in front of me is the person the proof is about?
The proof is bound to a key held inside the phone’s security chip, and the presentation is signed by that key against your own one-time challenge. That is a strong answer to “this device holds it”. It is a weaker answer to “this is the same human”, and we will not blur the two.
Do I have to store anything to prove I ran the check?
You store the result and the challenge you issued, both of which you generated. You do not store the person. What an auditor gets is an answer and a receipt, not a folder of strangers’ documents.
Does the organization that vouched for their age find out where they used it?
No. You never talk to that organization. You read what it published — its key and its status list — the way a browser reads any page, and it is never told who read it.
Can I use this today for a legally mandated age check in my country?
No — not on our say-so. What is real today is on the rows below, and the law that binds you is not something a vendor page should be interpreting for you. Read the rows, then take them to your own counsel.

One question asked. One answer sent. Nothing kept.