Prove you're human. Keep who you are to yourself.
Vouch is a human identity provider. A one-time government ID check (run by a regulated verification vendor) lets an online platform know an account belongs to a real, unique person. Vouch does not keep your ID or anything that ties the account back to you.
What we keep, and what we don't
- Never stored: your ID, photos or selfies, name, date of birth, address, document number, or the vendor's report.
- Stored: a keyed one-way fingerprint (a “nullifier”) of your document, separate for each platform, so one ID can back only one account per platform. It isn't linked to your account.
- Stored: a signed attestation that platform account X is human, so anyone can check it.
- Once the check is done we ask the vendor to delete the session data (redaction).
For platforms
- Public keys (JWKS):
/.well-known/jwks.json - Lookup:
GET /api/v1/lookup?platform=hip&account=<id> - Verify a token:
POST /api/v1/verify{"token":"…"} - Start a verification: send the user to
/verify?platform&subject&return_to&state&exp&sig(HMAC-signed by the platform)
configured issuer https://verify.gethip.app · vendor mock