GLOBAL ID NETWORK
Experimental prototype — not for real identity data

Verify who you are.
Disclose nothing else.

The Global ID Network lets a person prove a single fact — “I am over 18”, “I hold a valid identity issued in TW”, “I have an account in good standing” — through a one-time QR code that expires in five minutes. The backend never returns a birth date, a document number or the provider's raw reference: only the attribute that was asked for.

Create a demo account Sign in Open a verification link

Zero-knowledge style proofs

POST /api/verification/age answers OVER_18 / UNDER_18 with a single boolean. No attribute is disclosed beyond the requested check.

One-time QR, five minutes

QR tokens are stored as SHA-256 hashes, are single-use and self-expire. A database dump cannot be replayed into a proof.

Guardian consent for minors

A minor identity stays PENDING_GUARDIAN until an adult account approves the relationship, then activates to ACTIVE.

No raw external identifiers

Institutions send an external person id, but only HMAC(provider, id) is persisted — a cross-provider correlation key that cannot be reversed to the source document.

Strict CORS + rate limits

Origins outside the allow-list are rejected with 403 CORS_ORIGIN_NOT_ALLOWED, and every sensitive endpoint is limited per IP and per account.

Audit everything, store secrets never

Every state change writes an audit row. Passwords are PBKDF2-SHA256, sessions and API keys live only as hashes.

API endpoint

This page is static; it talks to the Cloudflare Worker. The current base URL is —. Change it for local development with ?apiBase=http://localhost:8787 — it is stored in localStorage.