Privacy-preserving proof of personhood

Proof you're a person.
Not who you are.

Give your platform confidence that every verified account represents a unique human — without ever collecting, seeing, or storing their identity.

What your site receives Verified
verified_human
true
sub
"hp_4f9c2e71a0b8…"
scope
"this site only"
Never shared
  • Legal name
  • Date of birth
  • Home address
  • Government ID number
  • Document images
  • Provider account ID

The problem

The Internet can't tell people from accounts.

One person can run a hundred accounts. A script can run a hundred thousand. Platforms are left choosing between abuse and intrusion.

Multi-account abuse is everywhere

  • Bots flooding sign-ups, reviews, and replies
  • Sock puppets manufacturing consensus
  • Ban evasion — a new account minutes after the last one
  • Fraudulent accounts exploiting promotions and trust
  • Coordinated manipulation of votes, polls, and rankings

Collecting IDs creates a new problem

Requiring government ID can stop some of this — but it turns every website into a custodian of passports, licenses, and home addresses.

That's a breach liability, a compliance burden, and a reason for honest users to walk away.

Human Pass separates proving someone is a unique person from revealing who that person is.

How it works

Verify once. Prove personhood anywhere. Reveal nothing else.

  1. 1

    User

    Chooses to verify when a site asks for proof of personhood.

  2. 2

    Trusted identity provider

    An established verification provider confirms the person is real. Their documents stay there.

  3. 3

    Human Pass

    Strips identifying data and derives a stable, site-specific pseudonym.

  4. 4

    Pseudonymous proof

    A signed assertion: verified_human: true plus a pairwise subject ID.

  5. 5

    Your website

    Enforces one verified person per account — without holding anyone's identity.

Who sees what
Identity providerHuman PassYour website
Name, ID documents, address Verifies Not passed through Never
"This is a unique, verified human" Yes Yes Yes
An ID that follows the user across sites Not shared Never issued Never

Privacy architecture

Same person. Unlinkable identifiers.

Every participating site gets its own pseudonymous ID for each verified person. It's stable on that site — so returning users are recognized and duplicates are caught — but meaningless everywhere else.

  • Minimal collection

    We keep only what's needed to issue consistent pseudonyms — not document scans, not profiles.

  • No unnecessary PII to sites

    Websites receive a yes-or-no answer and an opaque identifier. Nothing else by default.

  • Pairwise identifiers

    Identifiers are derived per site, so they can't be joined into a cross-site tracking ID.

  • Identity is not for sale

    We don't sell users' identity information. Our customers pay for assurance, not data.

One verified person forum.example hp_4f9c…a21e market.example hp_b73e…09dd social.example hp_19ad…c7e4
Stable per site. Different across sites. Returning to forum.example always yields hp_4f9c…. No two sites can compare notes to find the same person.

For platforms

Know they're a real person. Don't need to know who they are.

One person, one account

Enforce per-person limits with a stable identifier — and make bans stick without fingerprinting devices.

No identity data to guard

You never receive names or documents, so there's nothing sensitive to breach, retain, or explain.

One integration

Skip building verification infrastructure. A single, standards-shaped API instead of a vendor per region.

Less friction for real users

People are far more willing to prove they're human when they aren't asked to hand over who they are.

Built for services where unique humans matter

  • Social networks
  • Forums & communities
  • Marketplaces
  • Dating & community platforms
  • Voting, polling & governance
  • Reviews & ratings

Developers API concept

If you've added "Sign in with…", you already know how.

Human Pass is being designed around OAuth 2.0 and OpenID Connect. Redirect the user, receive a signed token, read two claims.

  1. 01

    Send the user to Human Pass with the personhood scope.

  2. 02

    They verify with a trusted provider — or reuse a prior verification.

  3. 03

    You get back a token with verified_human and a site-specific sub.

Interfaces shown are illustrative and subject to change as we work with early partners.

// Decoded token payload
{
  "aud": "your-client-id",
  "sub": "hp_4f9c2e71a0b8d35e…", // pairwise
  "verified_human": true,
  "iat": 1790467200
}
// No name. No birthdate. No document.

Vision

A personhood layer for the Internet — built on privacy, not surveillance.

Many providers, one API

Over time, Human Pass aims to sit in front of multiple trusted identity-verification providers, so platforms get broad coverage through a single integration and users can choose how they verify.

Free for people

Proving you're human shouldn't cost you anything. Human Pass is B2B infrastructure: platforms pay for assurance through subscriptions and low-cost proof requests.

Portable, not trackable

Verify once and prove personhood wherever it's asked — while every site sees a different identifier and none of them see you.

Get in touch

Help build proof of personhood the right way.

Human Pass is early. We're looking for design partners who want to shape it with us.

Identity-verification providers

Reach new relying parties through a privacy-first channel that never resells your users' data.

Platforms & communities

Join as an early adopter and help define the API, pricing, and policies around real abuse problems.

I'm reaching out as

We read every message and reply personally.