ProveKit is now open-sourced by World to enable private identity verification on regular smartphones.
The technology supporting World ID allows individuals to confirm their age, nationality, or possession of a valid ID without disclosing the personal information associated with it. World is unveiling one of the privacy technologies behind World ID, providing developers with a new method for identity verification that takes place directly on a user’s device instead of transmitting sensitive data to a third party.
The company has launched ProveKit, an open-source zero-knowledge proving toolkit that enables individuals to verify facts about themselves, such as age, valid identity document status, or fulfillment of nationality or residency criteria, without revealing their personal information.
For users, the practical advantage is clear. Instead of submitting a passport or ID card and relying on another company to protect it, individuals could potentially verify only the pertinent information. For instance, a service verifying whether someone is over 18 could receive confirmation that the age requirement is met without obtaining the person's name, date of birth, or a copy of their ID.
This release comes at a time when the dangers of the current system are increasingly evident. Security researcher Brian Krebs reported that a dark web entity named Nexus is selling digital scans of over 153 million driver's licenses from individuals in the United States and Canada, reportedly taken from a widely used identity verification provider serving multiple Fortune 500 clients. The FBI has begun an investigation into the breach's source, which allegedly includes front and back scans, infrared and ultraviolet images, and timestamps linked to routine activities like renting a car or visiting a dispensary, all gathered because a business requested to see an ID.
This is precisely the approach that ProveKit aims to avoid. Instead of individuals providing businesses their actual license or passport, which must then be stored and can become a target, ProveKit allows users to confirm only the necessary information, such as being over 18 or possessing a valid document, while the original ID remains on their device. Had the sensitive data at the core of the Nexus breach never been collected and stored centrally, it would not have been available for theft.
ProveKit generates these proofs locally on a smartphone or browser, meaning the underlying information does not need to be transmitted to an external server for processing. According to World, proofs can be generated in seconds on a standard smartphone and within 30 seconds on lower-end devices used during testing. The system can also function offline and with limited memory.
This characteristic could make zero-knowledge technology significantly more applicable outside of cryptocurrency. While privacy-preserving identity systems have existed for several years, creating complex cryptographic proofs has typically required substantial computational power and infrastructure, making implementation on regular consumer devices challenging. ProveKit is specifically designed to facilitate local proofs on the devices users already possess.
This technology is not merely experimental. ProveKit is already integrated into World ID, supporting privacy-focused verification within World’s identity network. For example, World ID Credentials can store information obtained from NFC-enabled identity documents locally on a user’s device, and ProveKit can then confirm specific attributes from these credentials without revealing the entire document. World claims that this underlying information remains inaccessible to World Foundation, Tools for Humanity, and other third parties, contrasting sharply with the centralized document storage involved in the Nexus breach.
For developers, World is releasing ProveKit as a ready-to-use, open-source codebase. It supports Noir, a Rust-inspired programming language developed by Aztec for creating zero-knowledge applications, allowing developers to generate various types of provable claims.
The toolkit is also designed with future security in mind. ProveKit aims for 128-bit post-quantum security, requires no trusted setup, and employs the WHIR hash-based commitment scheme. Its implementation has been reviewed and validated by Least Authority.
Making the technology accessible could broaden World’s privacy model well beyond World ID itself. Age-restricted websites, financial services, online marketplaces, travel platforms, and other applications often request users to submit more personal information than is genuinely necessary for verification, reflecting the over-collection pattern that enabled the Nexus service in the first place.
ProveKit offers an alternative model: verify the fact without disclosing the identity behind it.
World is also progressing on ProveKit v2, anticipated to create smaller and quicker proofs while decreasing memory demands and enhancing on-chain verification efficiency. As incidents like the Nexus breach urge companies to reconsider their handling of identity documents, tools like ProveKit suggest a method of conducting ID verification that does not endanger a collection of scanned licenses from the outset.
Other articles
ProveKit is now open-sourced by World to enable private identity verification on regular smartphones.
World has released ProveKit as open-source, a zero-knowledge proving toolkit that enables developers to create identity verifications that operate directly on users' devices. Individuals can validate their age, nationality, or possession of identification without disclosing the personal data associated with it.
