identity.org.au

identity.org.au is not an Australian Government service. It is an open-source community service stewarded by the not-for-profit DETIO Foundation, currently in the process of applying for accreditation under the Digital ID Act 2024. How this service is different

The service

Web wallet — my.identity.org.au

The browser portal for your Identity Wallet: manage credentials and consents, present proofs to services, and control your sessions — from any browser, with no password to phish.

Reference implementation · rolling out with the VirtEngine network

my.identity.org.au is the web wallet — the portal where your verified identity lives day to day. Verification evidence is captured once, on your phone, by the mobile wallet; the portal is where you use the result: presenting proofs, granting and revoking consent, and watching exactly what has been shared with whom.

https://my.identity.org.au my.identity.org.au Signed in with this device Your verified identity VERIFIED IDENTITY · VEID Verification level Standard Active Documents stay encrypted — this card holds results, not evidence Proofs you can present Over 18 Zero-knowledge proof — reveals nothing else Present Verification level — Standard Confirms your tier without your documents Present Residency — Australia Country only — full address never leaves Present Active consents Age check — marketplace service Expires in 30 days Revoke Tier confirmation — provider onboarding Single use · completed Review Consent history Granted · veid.trust_score · shown in plain language first Revoked · veid.document · future processing stopped Session security Signed in with a device-bound passkey — no password exists to phish Sessions expire automatically · sign out of all devices any time Every sign-in appears in your activity history

How signing in works

The portal never asks you to create a password. Sign-in uses passkeys and device-bound credentials — key pairs created in your device's secure hardware, where the private key never leaves. A sign-in is a cryptographic signature, not a shared secret: there is nothing for a phishing site to capture and replay, and nothing for a breached server to leak.

  1. Sign in with a device-bound credential

    The portal signs you in with a passkey or device-bound key — cryptographic material held by your device's secure hardware. There is no password to remember, reuse, or phish.

  2. Your wallet loads — results, not evidence

    The portal shows your verification level, available proofs and consent ledger. Your documents and biometrics are not in the portal; they stay encrypted where they were captured.

  3. Act, and everything is recorded

    Present a proof, approve or revoke a consent, end a session — every action lands in your auditable history, timestamped, visible only to you.

What you manage in the portal

  • Credentials. Your verification level and the verified claims behind it — with plain statements of what each one proves and never reveals.
  • Proof presentation. When a service requests a proof — over 18, residency, a tier confirmation — the request appears with the asker, the exact data involved and the purpose, and you approve or decline. See presenting proofs to a service.
  • Consents. Every active grant with its scope, purpose and expiry, plus one-action revocation and the full timestamped history — how revocation works.
  • Sessions and devices. Every signed-in browser and device, with the ability to end any session — or all of them — immediately.

Session security

Portal sessions are deliberately short-lived and re-authenticate for sensitive actions such as approving a new consent or removing a device. Signing out of all devices takes one action, and every sign-in — successful or failed — appears in your activity history. If a device is lost or stolen, the lost or new device guide covers the recovery path end to end.

What the portal deliberately does not hold is as important as what it does: no document images, no biometric templates, no raw evidence. If the portal's infrastructure were breached, the attacker's haul would be verification results and consent records — not the material needed to impersonate you. That is the same no-honeypot architecture the whole service is built on.

Maturity, stated plainly

The web wallet is part of the open-source VirtEngine reference stack and is rolling out with the network. Capabilities described here are the portal's design as implemented in the public codebase — we do not make availability claims beyond that, and any site other than my.identity.org.au claiming to be this portal should be treated as a scam.