World's ProveKit Can Verify Citizens, Hotel Guests and AI Agents Without Taking Their ID

I

Ishan Pandey

Guest
Coinbase's customer support agents were bribed in 2025 into handing over the records of about 69,000 customers, including images of their passports and driving licences. The attackers then demanded $20 million. Glassdoor users discovered in 2024 that the site had attached their real names to supposedly anonymous accounts. The European Union asks people signing a citizens' initiative in 17 member states for their passport or ID number. Each of these systems wanted to confirm one small fact about a person: that they own an account, that they work somewhere or that they are a citizen. Each of them collected the whole identity to do it.


ProveKit, which World open-sourced on 2 September and now uses inside World ID, turns that around. The phone reads the document, checks the one fact on the device and sends a short mathematical proof that the fact is true. The other side learns the answer and nothing else. I covered the release itself when it shipped. What follows are eight uses for it, each with the exact sentence the proof says, what the other side never sees and what a developer needs to build it.


7rEmNIeHNFOBfZZtUMQerOZIGGH3-lsa3ea1.jpeg


How a ProveKit Proof Works​


ProveKit reads four kinds of input. The first is the chip in an electronic passport, which more than 140 countries and organisations issue and which sits in over a billion passports, according to the International Civil Aviation Organization; the chip's data is digitally signed by the government that issued it, so a phone reading it over NFC can tell a genuine passport from a forgery without calling anyone. The second is a passkey, the login credential now used on about five billion accounts. The third is an anonymous credential, which lets a person prove they belong to a group and act once per app without the apps being able to compare notes. The fourth is anything a developer can describe in Noir, the programming language ProveKit compiles, which includes libraries other teams have already written, such as ZK Email's circuits for DKIM-signed email.


7rEmNIeHNFOBfZZtUMQerOZIGGH3-kk83eqx.jpeg


The developer writes the rule, for example "nationality is on this list" or "birth date is between these two dates". The user's phone runs the rule against the document and produces a proof under 1MB. Anyone with the matching verification key can check that proof on a server, on another phone or on a blockchain. The checker learns only whether the rule held. World's benchmarks put proving at 2 to 3 seconds on an iPhone SE 3 and under 30 seconds on a Motorola Moto E15 with 2GB of memory, both without an internet connection. The system needs no trusted setup, targets 128-bit post-quantum security and was audited by Least Authority.


7rEmNIeHNFOBfZZtUMQerOZIGGH3-p2c3eir.jpeg



1. Citizen-Only Petitions With One Signature Per Person​


A European Citizens' Initiative needs one million signatures from at least seven member states before the European Commission has to respond. Every signer hands over a full name plus either a home address and date of birth or, in 17 countries, a passport or ID number. Online petitions outside that system have the opposite problem: they collect little data and cannot tell a citizen from a bot or the same person signing ten times.


7rEmNIeHNFOBfZZtUMQerOZIGGH3-hib3e0s.jpeg



The proof says: "The holder of this valid passport is a citizen of an EU member state, old enough to sign and has not signed this petition before."

The organiser never sees: the name, passport number, date of birth, address or which member state.

The passport chip supplies nationality and birth date, the rule checks them against the list of member states and the minimum age. The proof carries a code tied to this person and this petition. A second signature from the same passport produces the same code and is rejected, while the same person's code on a different petition is unrelated, so no one can build a list of everything a citizen has signed. The EU initiative's own data rules would have to change to accept this, but national parliament petitions, city consultations, citizens' assemblies and community votes can use it now.

What it takes: ProveKit's published passport circuit, a short Noir rule for the member-state list and age, plus the one-per-person code World ID already uses.


2. Nationality Pricing at the Taj Mahal Gate​


Many monuments charge by nationality. The Taj Mahal's entry fee is ₹50 for Indian citizens, ₹540 for visitors from SAARC and BIMSTEC countries and ₹1,300 for other foreign nationals plus ₹200 for the mausoleum, according to Agra's licensed guides. Staff can ask for a passport to check that the ticket matches. The same tiered pricing exists at national parks, heritage sites and museums from Peru to Egypt, where each check means a stranger handling a traveller's passport.


7rEmNIeHNFOBfZZtUMQerOZIGGH3-jfg3ek7.jpeg



The proof says: "The holder of this valid passport is a national of one of the countries eligible for this ticket price."

The ticket office never sees: which country, the name, the passport number or the photo page.


The visitor proves eligibility when buying the ticket online. The ticket office issues the ticket against the proof. The same rule works for any "residents pay less" scheme that is based on nationality. It can be updated when the list of eligible countries changes, because the list is a public input the verifier supplies. It covers anyone whose passport carries a chip.


What it takes: the passport circuit plus a Noir rule that checks nationality against a list.


3. Children's Spaces That Adults Cannot Enter​


Age gates usually keep children out. Roblox's problem runs the other way: since January it has required a face-based age check for chat worldwide, sorting users into under 9, 9 to 12, 13 to 15 and 16 and over so that children under 16 cannot message adults. Its face-estimation vendor is accurate to within 1.4 years on average for minors. For a system meant to keep a 17-year-old out of a room of 12-year-olds, 1.4 years is a wide margin.


7rEmNIeHNFOBfZZtUMQerOZIGGH3-awh3e8p.jpeg




The proof says: "The holder of this valid passport was born between these two dates," which places them exactly in the 9 to 12 band.

The platform never sees: the child's name, exact birthday, photo or nationality.

A parent taps the child's passport against the phone once. The platform receives an exact age band rather than an estimate from a camera. Not every child has a passport, so this sits alongside face estimation rather than replacing it, but for families that have one it gives certainty with no image captured at all.

What it takes: the passport circuit plus a Noir rule comparing the birth date with two boundary dates.


4. Reviews Only Verified Guests Can Write​


7rEmNIeHNFOBfZZtUMQerOZIGGH3-tli3ec2.jpeg


Trustpilot removed 4.5 million fake reviews in 2024, 7.4 percent of everything submitted. The US Federal Trade Commission banned reviews from people with no real experience of a business, including AI-written ones, in August 2024. Platforms fight fakes by asking reviewers for booking numbers or receipts, which ties every review to a named customer the business can look up.

The proof says: "The writer stayed at this hotel this month and has not reviewed this stay before."

The hotel and the review site never see: which guest wrote it, the room number or the booking name.

At checkout, the hotel's system issues the guest an anonymous credential for that stay, which sits on their phone. When the guest writes a review, the phone proves it holds a valid credential for this hotel and this month, with a one-per-stay code so the same guest cannot post twice. The hotel can confirm every review came from a real guest and still has no way to find out who wrote the bad one. The same pattern works for restaurants, doctors, landlords, online courses and any seller that can hand out a credential at the moment of purchase.

What it takes: ProveKit's anonymous-credential flow, with the business acting as issuer.


5. Anonymous Workplace Reviews From Verified Employees​



Workplace review sites face a contradiction. They need to know reviewers really work where they say, but reviewers need to be untraceable or they will not be candid. Glassdoor's attempt to verify users through its Fishbowl network led to real names appearing on accounts people believed were anonymous.

The proof says: "The writer can receive email at an @acme.com address and has not reviewed Acme this year."

The review site never sees: the email address, the name or the team.

Every work email carries a DKIM signature from the company's mail server. ZK Email's Noir library, audited by Consensys Diligence, can prove that a signed email was sent to an address at a given domain while hiding the address itself. Because ProveKit compiles Noir, it can run that proof on the employee's phone. The same proof lets a journalist confirm that a source really works at the company they are describing without the source ever sending a traceable email to the newsroom.

What it takes: ZK Email's Noir circuit compiled with ProveKit, plus a one-per-person code derived from the hidden address. The ZK Email circuit has not yet been benchmarked on ProveKit.


6. Account Recovery Without a Stored Passport​


7rEmNIeHNFOBfZZtUMQerOZIGGH3-7yj3edl.jpeg



When a customer loses a phone or a password, exchanges and banks fall back on a support agent comparing a fresh ID photo with the one on file. That file is what the Coinbase attackers bought: the agents they bribed could look up customers' government ID images because recovery depends on keeping them.

The proof says: "This is the same valid passport that was used to open this account."

The platform and its support staff never see: the passport, at sign-up or at recovery.

At sign-up, the phone reads the passport chip and computes a one-way fingerprint of its signed data. The platform stores only the fingerprint. At recovery, the customer taps the same passport and proves it produces the same fingerprint and has not expired. A support agent with full database access has nothing worth selling, since the fingerprint cannot be turned back into a passport. A SIM-swapper who talks their way past support still cannot produce the proof without the physical document.

What it takes: the passport circuit plus a Noir rule that hashes the chip's signed data and compares it with the stored fingerprint.


7. Spending Limits for AI Agents Signed by a Human​


7rEmNIeHNFOBfZZtUMQerOZIGGH3-i3k3eip.jpeg



AI agents are starting to book flights and pay invoices on people's behalf. The merchant on the other end has no way to know whether a person approved the purchase or the agent decided on its own. World ID's partners are already working on this: Vercel on human-in-the-loop checks for agent workflows and Okta on attaching a verified human to API calls.

The proof says: "A verified human approved this order with their passkey. It is below the $300 limit they set for this merchant."

The merchant never sees: who the human is, which account or device signed or what the person's limits are elsewhere.

The person sets a limit once and approves each purchase with a passkey on their phone, the same tap they use to sign in to a bank. ProveKit turns that approval into a proof that covers the signature, the amount and the merchant. The agent attaches it to the order. The merchant can refuse any order that arrives without one. Because the limit is checked inside the proof, an agent that tries to spend $3,000 cannot produce a valid proof at all.

What it takes: ProveKit's WebAuthn passkey circuit, which World has already benchmarked, plus a Noir rule for the amount and merchant.


8. Offline Aid Distribution on Low-End Phones​



7rEmNIeHNFOBfZZtUMQerOZIGGH3-p1d3ev0.jpeg



Humanitarian agencies need to confirm that each person receiving cash or food is eligible and collects only once. The usual answer has been a central biometric database, a model that came under scrutiny when Human Rights Watch reported that data collected from Rohingya refugees had been shared with the government they had fled.

The proof says: "The holder is registered for this programme and has not collected this round's distribution."

The distribution point never sees: a name, a fingerprint, a face or a registration number.

The agency issues each registered household an anonymous credential on its own phone. At each distribution, the phone proves the credential is valid with a one-per-round code. The volunteer's phone verifies it with no connection. This depends on the proof running on the phones people in those settings actually own, which is the case World designed for: its slowest test handset, a Moto E15 with 2GB of memory and a 32-bit processor, finished proofs in under 30 seconds. ProveKit keeps memory under 1GB, while the same passkey check built on the older Circom stack needs a 1.73GB buffer, enough to crash a phone like that.

What it takes: ProveKit's anonymous-credential flow, with the agency as issuer, plus the offline prover and verifier that ship with the toolkit.


What Comes Next​


World's next version moves ProveKit to a smaller number field called Goldilocks and adds a Groth16 backend, which the team expects to cut proof size, proving time and memory and to make on-chain checks cheap. That matters most for the petition, review and agent cases, where thousands of proofs may need to be checked or stored. The passport-based cases also depend on the document itself, so they cover people whose passports carry a chip from countries whose signing certificates are published.


Every one of the eight systems above exists today in some form. Every one of them works by collecting more about a person than it needs and keeping it somewhere it can be bribed out, breached or misused. The circuits for passports, passkeys and anonymous credentials are already public. A developer can write each new rule in a few lines of Noir. The first petition site, review platform or aid agency to ship one of these will be asking its users for less than any competitor while holding nothing worth stealing when the next breach comes.


Don’t forget to like and share the story!
 

Thread statistics

Created
Ishan Pandey,
Replies
0
Views
3
Back
Top