identity.org.au

identity.org.au is not an Australian Government service. It is an open-source community service stewarded by the not-for-profit DETIO Foundation, currently in the process of applying for accreditation under the Digital ID Act 2024. How this service is different

Using your wallet

Using your wallet with a service

The step-by-step of what happens when a website or business asks you to prove something with your Identity Wallet.

Last updated 20 July 2026

When a participating service needs to know something about you — that you are a real, verified person, that you are over 18, or that your identity meets a certain level — it asks your wallet, and your wallet asks you.

What the flow looks like

  • The service tells your wallet what it is asking for and why — for example, “verification level Standard, to open an account”.
  • Your wallet shows you the request in plain language: exactly which data or answer will be shared, with whom, and for what purpose.
  • You approve or decline. Nothing is shared until you approve.
  • If you approve, the wallet shares only the agreed answer — never the underlying documents.
  • The consent is recorded, and you can see it (and revoke it) in your consent history at any time.

What the service receives

Services receive the minimum needed for their stated purpose: your verification level, and the specific answer you approved. For age checks, the network can produce a zero-knowledge proof — a cryptographic yes/no that proves the claim without revealing your birth date or your document.

If a service asks for more than it needs — for example, requesting your full document scan — that request cannot be fulfilled through the wallet. The protocol only shares verification results and consented claims.

Saying no

Declining a request costs you nothing within the wallet — there is no penalty, no score change, and no record shared with the service beyond the fact that the request was not fulfilled. A service may choose not to serve you without verification, the same way a venue can decline entry without ID.

Time-limited and service-specific consent

Consent can be scoped to a single service and given an expiry date — for example, 30 days. When it expires, the service loses access automatically, without you having to remember to revoke it.