identity.org.au

The Identity Wallet service

Prove what matters. Keep the rest private.

The Identity Wallet keeps your identity on your phone, encrypted. When a service needs an answer, such as whether you are over 18, it gets the answer, never your documents.

Free, open source, and operated by a not-for-profit foundation. Independent of the Australian Government.

identity.org.au · specimen

Verified · Standard

Claim
Over 18
Result
Yes
Record
IDAU-0001
Documents
Not shared

IDAUASPECIMEN<<PROOFCLAIM<OVER18
IDAU0001<AUSRESULT<YES<<DOCS<NONE

Specimen card. The service receives the claim, not the document.

The service

One verified identity, two wallet surfaces

Verify once on your phone; manage everything from the browser. Your verification level works everywhere the VirtEngine network is accepted — as an approved client, providers see your tier, never your documents.

Everyday uses

What you can do with the Identity Wallet

  1. 01 Verify your identity once Complete a guided verification on your phone, then reuse it everywhere the wallet is accepted.
  2. 02 Prove your age without your documents Answer whether you are over 18 with a cryptographic yes. Your birth date and documents stay private.
  3. 03 Share with services on your terms See exactly what a service is asking for, approve or decline, and set consent to expire.
  4. 04 Change your mind, any time Every consent you grant can be revoked. Every use of your data is recorded where you can see it.
  5. 05 Build a stronger verification level Four levels, from Basic to Trusted, unlock more as your identity evidence gets stronger.
  6. 06 Leave, completely Delete your identity data on a published timeline. Encryption keys are destroyed, so deletion is real.

In everyday use

Prove the thing. Keep the document.

A selfie with a live challenge is how the wallet knows a real person is present. The photograph is evidence for one verification — never a profile picture, never shared with the services you use.

A person holding a phone at arm's length to photograph themselves.

A live check in ordinary light: what the wallet needs is a moment of presence, not your archive.

Get started

Set up in about ten minutes

You need a smartphone and a government-issued identity document. The wallet guides you through each step, and you review everything before it is submitted.

  1. Step 1 of 3: Scan your identity document

    Front and back, guided by the camera. The app reads the details and you check them before anything is submitted.

  2. Step 2 of 3: Take a selfie with liveness checks

    Blink, turn your head, smile — short challenges that prove a live person is present, not a photo.

  3. Step 3 of 3: Review and submit — encrypted

    Everything is encrypted on your phone before it leaves. The network verifies your identity and issues your verification level.

See the full setup guide
Share only what's needed Zero-knowledge proof Prove the answer — keep the data STAYS ON YOUR DEVICE — ENCRYPTED Full name Date of birth Address Document number SHARED WITH THE SERVICE Over 18 — yes One answer. Nothing else leaves. The service can verify the proof is genuine without ever seeing your information. Share proof
Zero-knowledge sharing in miniature: private fields stay locked, and one checkable answer leaves the phone.

Verification levels

Four levels. Services ask for what they need — no more.

Verification levels, what each is based on, and what it unlocks
Level In plain terms Typical use
Unverified You have a wallet, but no identity checks have been completed yet. Browsing services that accept the wallet
Basic Early checks have passed. This level can support a limited claim when a specific service asks for it and you choose to present it. A specific offer's disclosed proof request, when the current service supports it
Standard A verification scope has been completed. Original identity document images and full OCR output stay on your device; only separately approved derived data may be submitted. Age and attribute proofs (for example, proving you are over 18)
Trusted The strongest level: everything in Standard, plus hardware-backed biometric checks, device integrity attestation, and a sustained verification history. Protocol roles or services with separately disclosed, supported proof requirements
Verification levels in detail — what evidence each requires

Your data, in plain terms

Locked on your device. Processed in a vault no one can open.

Original document images stay on your device. The wallet processes them locally; only minimum, user-approved derived data may leave, encrypted for VEID verification.

  1. Stage 1 Captured On your phone: document scan, selfie, liveness.
  2. Stage 2 Original stays local The document image never leaves your device. OCR and checks run locally.
  3. Stage 3 Derived data, if approved Only minimum user-approved fields may leave, encrypted for VEID processing.
  4. Stage 4 Transient data cleared Temporary processing data is cleared under the scope lifecycle; source images remain local.
  5. Stage 5 Selective result The network records the verification result and required encrypted references, never source images.
Original document images stay on your phone. Only minimum, user-approved derived data may leave, encrypted for VEID verification.
Where each category of identity data is stored
Your data Where it lives Who can read it
Document scans and photos Original images stay on your device; only approved derived data may be submitted encrypted You control the image. The network receives no document scan.
Biometric templates Encrypted before leaving your phone (X25519-XSalsa20-Poly1305) Never shared with services. Never sold — prohibited regardless of consent.
Verification results On the network — your level and pass/fail outcomes Services you explicitly consent to, per request.
Consent records Auditable history — every grant, every revocation, timestamped You, in full. Services see only their own grants.

Insights

Analysis on digital identity

Evergreen explainers on fraud, architecture, cryptography, consent and rights.

All insights Guides Definitions

Trust

Why you can check our claims

Open source

Every line of the wallet and the network is public. Nothing on this site asks you to trust what you cannot inspect. About the code

Not-for-profit foundation

Operated by DETIO FOUNDATION LTD (ACN 699 651 771), with a constitution that directs assets and income toward its public-benefit purposes. Who runs it

Patented method, public interest

The verification method is Australian patent AU2024203136B2, held inside the public-benefit structure. The patent in plain terms

Honesty first

This wallet is a working, open-source reference implementation — the blueprint production wallets build on. There are no app-store listings, and we make no claims of government accreditation. What we publish here is what the code does.

Get your wallet

Your identity should not live in someone else's database.

Join the launch list for the January 2027 rollout, follow the build in the open-source repository, or read exactly how your data is protected.