What is Attest ID?
The problem
- 950M+ credentials issued annually worldwide — degrees, licenses, certifications.
- Verification today is analog: phone calls to registrars, mailed transcripts, PDF inspection.
- None of it works instantly or across borders.
The solution
- W3C Verifiable Credentials — standard JSON-LD shape, not a proprietary format.
- Ed25519 signatures (RFC 8037) — issuer signs, anyone can verify offline against the issuer’s public key.
- DID-based issuer registry — a directory of trusted issuers and their current/historical keys.
- No blockchain dependency — cryptography alone solves verification; ledger-based trust can be added later if governance ever requires it, not before.
Who uses it
| Actor | Does |
|---|---|
| Issuer | Signs and issues credentials (custodial or bring-your-own-key) |
| Holder | Owns credentials, controls who can view them, sees an access log |
| Verifier | Checks authenticity in seconds, no registrar call needed |
| Custodian | Bulk-attests to documents it collected but did not originally issue |
| Admin | Approves issuers/custodians, governs the shared catalog, watches system health |
Design principles
- Open standards only — no proprietary formats, no vendor lock-in.
- Independent deployability — every service owns its schema, API, release cycle.
- Holder agency — holders control access; every access is logged and visible to them.
Current status and backlog
Attest ID has no phase plan — work is tracked as a flat, priority-ordered backlog, not calendar
phases. The root CLAUDE.md’s “Roadmap Context” section (in the repo, not this site) is the
single, actively-maintained source for what’s built versus what’s still open before launch — read
that instead of a second copy here.