About Identiq
Verify once, not on every app you sign up for
Every app that needs to know you're a real, verified person today asks you to upload a passport again. Identiq exists to break that loop: verify once, then grant each app a scoped, expiring, revocable permission to check the result. The app gets a pass/fail answer — never the document.
Principles
What this is built on
Three rules, held to deliberately — see the security page for how each one is actually enforced in code.
Never take custody of your keys
Registering your identity and granting permissions are actions only you can authorize. Identiq builds the transaction; your own wallet signs it. We never hold a signing key that could act as you.
Never store raw evidence
When a credential is issued, only a hash of the evidence checked is kept — never the document itself. A credential can be independently re-verified without Identiq, or anyone else, holding the original file.
Every check is permissioned, not public
An app can only read a credential's status if you've granted it a scoped, expiring permission for that specific credential type. Nothing is visible by default, and every grant can be revoked instantly.
Where this is today
Honest status
Identiq runs on Stellar's public testnet today, not mainnet — it's free to use while that's true. The identity registry is a real, tested Soroban smart contract; the API, dashboard, SDK, and CLI are all fully functional against it.
Next up: zero-knowledge proofs, so a credential's result can be proven without revealing the underlying data even to Identiq itself, and a mainnet deployment with usage-based pricing.
The full source — contract, API, SDK, CLI, and this site — is public on GitHub.