How it works
Three moves.
One
You make a mark
It is made on your device and it is yours.
It looks like nothing in particular, which is the point: it identifies you without saying anything about you. Show it, read it out, print it on a card, let it be scanned. Whatever you are asked to prove, and whoever is asking, it is the same mark.
Two
Someone asks you something
An employer. A landlord. A client. A site. A service that has to check your age.
They send a link that says who they are, why they are asking, and exactly what they want to know. You see all of it before anything happens, and you can turn it down.
Three
Your device answers
Most questions have a yes or a no.
Are you over 18. Is your licence current. Is your cover in date. Are you cleared for this site. Your device works that out from what it holds and sends the answer, not the document. Where somebody genuinely needs a value, they have to ask for it as one, and you see that before you send.
You both end up with a receipt. You can see everyone you have answered, and you can withdraw at any time.
The limits
What this does not do yet.
They are tied to an identity that travels with you and cannot be borrowed, which is a real improvement on a typed form. But an answer only becomes independent when the organisation that issued a credential vouches for it directly. Those connections are being built one at a time. Until one exists you will see the answer described as yours, not as verified.
Checking that a face matches a document happens between two people in a room, and it always did. What changes is that afterwards nobody keeps a copy. They keep a record that the check happened.
Make a backup and keep it somewhere safe. Nobody can recover it for you. A recovery route would mean somebody else holding your identity, and that is the thing being removed.