Identity without oversharing, explained simply.
See how a person can prove “I am unique”, “I am over 18” or “this account is really mine” without handing every service a copy of the evidence.
.zkdid® is being designed as an open trust layer that lets people prove they are unique, and lets agents and devices prove they are genuine, without placing raw identity data inside a company or government database.
See how a person can prove “I am unique”, “I am over 18” or “this account is really mine” without handing every service a copy of the evidence.
Today, proving who you are often means handing organisations copies of passports, biometrics or personal records. .zkdid® is designed so a service can check the one fact it needs, such as “one real person”, “over 18”, or “the same trusted device”, without receiving the underlying identity data.
The service may receive far more than an age and personhood check requires.
Your wallet uses an accepted credential to answer the specific request.
Personhood passed · User eligible · Fresh proof
Every copied document creates another database that must be trusted, secured and governed fairly.
DNS helps the internet find websites. .zkdid® applies a decentralised version of that shared naming idea to identity proofs, so wallets and services can resolve trust without one company owning the registry.
.zkdid® aims to make trust reusable across services while keeping the person, not a platform, in control of the keys and evidence.
The dedicated .zkdid® namespace is designed to give verified people a shared place to interact online. Private proof gates entry, a holder-controlled root carries membership, and decentralised resolution lets compatible services recognise that membership without relying on any single company’s centralised directory.
Root updates are committed to shared, cryptographically linked state, making silent rewriting harder.
Each holder-controlled .zkdid® root resolves without relying on one private directory.
One person-bound credential is issued only after uniqueness and eligibility checks.
A fresh proof unlocks the service without exposing the identity evidence behind it.
Blockchain anchors the shared state. Decentralised DNS resolves the membership root. Personhood checks resist duplicate identities. Zero knowledge proves valid access privately. No single layer does the whole job.
Root updates can be checked against shared chain state. Cryptographic linking makes undisclosed alteration evident.
Members control their keys while compatible services resolve verification material without one platform owning the directory.
Only a wallet presenting a fresh proof of valid, current and person-bound .zkdid® membership can enter.
Duplicate-resistant enrolment limits one person from multiplying accounts, access or votes within the defined network.
Duplicate-resistant enrolment can stop one person multiplying fake memberships. It cannot prove that an admitted human will behave honestly; eligibility rules, revocation, moderation and redress still matter.
A shared chain removes a single private database and makes interference harder to hide. Apps, gateways, governance and the underlying chain can still be attacked or pressured.
Your keys and credentials stay on your device. It creates a fresh proof for the specific request, the .zkdid® root helps the verifier check it, and the service receives an answer, not your raw identity.
The user begins locally. Keys stay device-bound, and no raw biometrics or personal documents leave the phone.
Swipe or tap the phone to move through the steps.
The architecture keeps identity existence separate from service-level authorisation, so policy can sit above the root without one actor becoming the power to erase participation.
Tap a node in the diagram to open the matching layer below. The point is simple: sovereignty improves when existence, proof, policy and governance are not collapsed into one controllable chokepoint.
.zkdid®
trust root active
The root should remain resolvable as infrastructure, not become a switch one institution can use to erase participation.
Services receive fresh proof material for the interaction, not a reusable identity profile or raw biometric record.
Apps and institutions can set access rules higher up, while the trust anchor itself stays neutral and auditable.
Open standards, public artefacts and decentralised governance reduce the risk of platform or registry capture.
This root site frames .zkdid® as a living public-interest protocol initiative rather than only a funding document.
A visitor should be able to see the core principle: the person keeps secrets local, the trust layer anchors proof, and the service verifies only what it needs.
Human, agent or device keeps keys and sensitive source material local.
Commitments, resolver material and continuity live below service policy.
The service checks proof without taking ownership of the underlying identity.