Preview: wellknown.id is in development and isn’t live yet

Uses · Age verification

Prove you’re over 18, and nothing else.

A site that has to know you’re an adult asks one question: are you over 18? With kivi the answer is a yes or a no. Your name, your birthday and your photo stay on your phone.

The usual way

Showing everything to prove one thing.

Most age checks ask for a photo of your passport or a selfie, or for a card number, and some keep what they were given. To prove you were born before a certain day, you hand over your name, your date of birth, your document number and your face, to a company you may never have heard of, and trust it to look after them.

That’s a lot of risk for one yes. A site that never holds your date of birth can’t lose it, sell it or be made to hand it over.

How it works

Four steps, and one of them is yours.

  1. Read your document once. Point your phone at your passport or ID card, then hold it against the card. kivi reads the chip and checks that the issuing country signed its data and that the chip is genuine, not a copy. The document stays on your phone.
  2. A site asks one question. The site asks for “over 18”, through the browser’s Digital Credentials API, in the standard way wallets are asked for credentials (OpenID4VP).
  3. You see what would be shared. kivi shows who is asking, for which site, and exactly what it would send, with what the site says it will do with it. You approve it, or you don’t.
  4. Only that claim leaves. kivi answers “over 18” and nothing more. The answer is signed with a key held in your phone’s secure hardware and bound to that site and that request, so it can’t be reused somewhere else.

Who learns what

Each side sees only its own part.

  • The site learns that the holder of a checked document is over 18. It doesn’t learn your name, your date of birth, your document number or your photo.
  • wellknown.id learns nothing. The answer goes from your phone to the site.
  • You keep a record. What you shared, and with whom, goes into your own consent records: signed by your phone, encrypted so only your devices can read them, and yours to export.

What to know

What works today, and what doesn’t yet.

  • Works now: reading and checking UK passports and Estonian ID cards, on Android and iPhone; and answering sites through the browser’s Digital Credentials API, on Android.
  • Not on iPhone yet. kivi on iPhone reads and checks your document, but doesn’t answer sites yet.
  • From a laptop: kivi on your phone, bonded with kivi in your laptop’s browser, answers kivi’s own test verifier. Other sites asking that way need a route to kivi first, which is still to build.
  • Self-issued, so only as strong as your phone. kivi checks your document’s chip itself and signs the claim itself. A site decides how far to trust that, and kivi shows how far the document was checked. If a site wants more, wellknown.id can act as a witness that checks the chip and vouches for it; that’s in preview, with a legal review first.
  • Other ages too. kivi can answer for 13, 16, 18, 21 and 65, the same way.
  • Still to come: showing it in person, at a door or a till (On the high street), and zero-knowledge proofs over your document’s own signature, once they’re mature enough to rely on.

wellknown.id is in development. This page says what works now, and nothing more.

For sites

Asking for it.

A site asks for the standard claim age_equal_or_over.18 from the EU’s PID format, so it works with other wallets that answer the same request. It checks the signature and the binding to its own origin, and keeps only the result. See the developer notes, or try the test verifier at kivi.wellknown.id/verify.