I’m building a product
Integrate on the sandbox first (free test verifications, simulated chain, bi_test_ keys), then take production traffic on Builder or Growth. Marketing checkout issues production keys.
Start on the sandboxIdentity Inc.
Most people quit when an app asks for a passport on day one. Identity Inc. lets users start after a quick email and phone check, asks for ID only when it is actually required, and gives you proof a regulator will accept — without your team ever storing a passport photo.
For wallets, fintechs, marketplaces, and banks. Free to build on — $99/mo when you go live. Need a personal blockchain account instead? Create one on Blocksfinity.
This site is for teams adding identity to an app. If you just need a free personal blockchain account, that flow lives on Blocksfinity.
Integrate on the sandbox first (free test verifications, simulated chain, bi_test_ keys), then take production traffic on Builder or Growth. Marketing checkout issues production keys.
Start on the sandboxCreate a provisional Vaulta account: confirm email and phone, verify when asked, choose a name, and keep your keys. No $99 platform fee — that is for apps, not people.
Continue on BlocksfinityIf your app touches money, goods, or anything regulated, you have to know who your users are. Today that usually means choosing which price you would rather pay.
Option 1
You ask for a passport before the person has seen what your product does. Most of them never come back — and you pay for the check either way.
Option 2
Signup is effortless, but you cannot offer anything regulated, and one person with a script can open a thousand accounts on your free tier.
Option 3
Choose a vendor, store the results, secure the passport images, build the audit trail, keep re-screening against sanctions lists, handle deletion requests. Months of work, and then it is yours to maintain forever.
Identity Inc. is the fourth option: everyone gets in immediately, and only the users who need to be verified ever are.
Email and phone first — that is how we reach them, not who they are. ID is asked only when your rules require it. You store no identity documents at any point.
Signup starts with an email code and a phone code. That proves the account is reachable for notices — it is not identity verification, and it never creates a verified person.
For developers: Contact proofs are sealed at rest and uniqueness-hashed. Confirming a code never promotes a Person; KYC remains the only identity claim.
They choose an account name. We create and fund a blockchain account for them so they can start using your app under limits — no passport required.
For developers: Sponsored account creation plus a user-chosen name. Your backend stores the account ID we return.
New users can look around and do low-risk things. You decide where the ceiling sits. Identity documents have still not been collected.
For developers: Transaction costs are sponsored. Email and phone are on file; no KYC result exists yet.
The first time a user does something that needs a real identity — a withdrawal, a payout, a loan, a large trade — they verify. Photo of an ID and a selfie, done in minutes, inside your app.
For developers: Runs on your identity verification provider (live: Shufti Pro). The documents stay there; we keep the outcome and a hash.
The user signs a one-time challenge on their own device. That is what makes “verified” impossible to sell, share, or reuse somewhere else.
For developers: The signature binds the person to the account and issues a signed credential you can verify yourself.
Screening keeps running in the background, and every decision is written to a log that can be exported and proven unaltered when someone asks.
For developers: Sanctions and politically-exposed-person flags, ongoing monitoring hooks, and a hash-chained audit export.
Because a verification provider answers one question, once: is this document real, and does the face match? Everything after that answer is yours to build. That everything-after is the product — and it works with the provider you already use.
| The job | On your own | With Identity Inc. |
|---|---|---|
| Checking that an ID document is genuine | Your identity provider does this well. So do we — we call the same kind of provider. | Same check, through the provider you choose. This part is not the hard part. |
| Holding the passport photo and the selfie | They land in your storage, and the breach risk, the encryption, and the audit scope are now yours. | They stay with the verification provider. You receive a signed result and a fingerprint of the document — never the document. |
| Tying a verification to one account | You write the logic yourself, and nothing stops the same approval being reused on another account. | The user signs with the private key on their own device, so a verification belongs to exactly one account and cannot be transferred. |
| Proving it a year later | You go digging through database rows and application logs, and hope nobody edited them. | One export, cryptographically chained, so you can show an auditor that no record was altered or removed. |
| Sanctions and watchlist screening | A second vendor, a second integration, and a scheduled job you have to keep alive. | Screened when the person verifies and re-screened over time, with flags on the record and a freeze switch for your compliance team. |
| Launching a second product | Your users verify all over again, and you integrate all over again. | One verified identity works across every app you run, with separate keys and separate policy per app. |
| Fake accounts and repeat fraudsters | Rate limits you invent, tune, and maintain yourself. | Signup velocity limits, shared-device clustering, and access that only widens after a clean verification. |
| Time to first working flow | Weeks of integration, then permanent maintenance. | An afternoon with the API. Free while you build, $99 a month once you are live. |
We are not a replacement for your verification provider. We are the layer that turns their answer into something you can rely on, reuse, and prove.
The rule is usually the same — verify the person before money moves. What changes is the moment it applies.
Let someone create a wallet and hold funds in seconds. Ask for identity at the withdrawal or the fiat on-ramp, which is where the rule actually applies.
Onboard, screen against sanctions lists, and keep evidence your regulator will accept — without building a document vault or a screening pipeline in-house.
Verify the people who receive money — sellers, drivers, earners — at the point of their first payout, not at the point they sign up and might leave.
Sits alongside your core systems: signed requests, IP allowlists, company verification for business customers, a service-level agreement, and a data processing agreement.
More signups completed, less fraud, and a far smaller compliance problem — from one integration.
Nobody is asked for a passport just to look around. The ID check arrives at the moment the user already wants something from you, which is the moment they will actually complete it.
Passport photos and selfies stay with the verification provider. You keep a signed result instead — a much smaller thing to secure, and a much smaller thing to explain after an incident.
Sanctions screening, an exportable audit trail that can be proven unaltered, retention rules, and a freeze switch — included, rather than six months of your roadmap.
One integration serves every product you run, each with its own key and its own policy. Launch the second app without making your users start over.
Every verified person is screened against sanctions and politically-exposed-person lists, then re-screened over time — with no ID documents kept on your side.
Everyone who verifies is checked against sanctions lists and politically-exposed-person lists — people whose public position makes them higher risk to serve.
Lists change, so people are re-checked afterwards. None of it requires you to collect or store their documents again.
Your compliance team can suspend an account in one click, with the evidence attached to the record for whoever reviews it next.
Signup limits, shared-device detection, and access that only widens after verification — so nobody farms a thousand accounts out of your free tier.
Caps per network address, per device, and per day, so free accounts cannot be created in bulk.
Accounts created from the same device or key are clustered together, which is how one person running hundreds of accounts becomes visible.
Limits only widen after a real verification and a clean risk score. New accounts never start with full access.
One integration covers every app you run — wallet, marketplace, or core banking. Build free today, go live for $99 a month.
The questions we get on every first call.
It lets people join your app after proving an email and phone, verifies their identity only at the moment you actually need it, and gives you signed proof of that verification — so you never have to store passport photos or selfies yourself.
Two at once. You stop losing new users to an ID check they were asked for too early, and you stop being the company that holds a database of passport images. You also get the sanctions screening, audit trail, and anti-fraud limits that you would otherwise have to build and maintain yourself.
A KYC (Know Your Customer) provider answers one question, once: is this document genuine, and does the face match? Everything after that is yours to build — storing the answer, tying it to a specific account so it cannot be reused, proving it to an auditor a year later, re-checking the person against sanctions lists, and stopping one individual from opening five hundred accounts. Identity Inc. is that everything-after-that layer, and it works with the KYC provider you already use.
One server-side integration. You call the API from your own backend, collect contact proofs, create the account, start KYC when your rules require it, bind the result, and read a status back. Typical first integration takes an afternoon. Your app never handles identity documents or secret keys in the browser.
No. Every user gets a free blockchain account behind the scenes because that is what makes a verification permanent and non-transferable, but we create and fund it for you and your app never has to think about it. If you are already building on the Vaulta (Antelope) network, you get direct access to the same accounts.
Not by Identity Inc., and not by you. Photos of IDs and selfies stay with the identity verification provider that captured them. Identity Inc. keeps only the outcome, a reference number, and a fingerprint (hash) of each document — enough to prove a check happened, not enough to leak someone's passport.
After the check passes, the user signs a one-time challenge with the private key on their own device. That signature is what ties the verification to one specific account, and it is recorded in a tamper-evident log. A verification that was not signed by the account holder is not accepted.
Yes. Use the sandbox at sandbox.identityinc.io for free test verifications against the real provider and a simulated chain. Builder is the free platform tier on production (identity checks there are billed by your verification provider). Growth is $99 per month and raises the limits: 10,000 verifications a month, 5,000 sponsored accounts a day, 600 requests a minute, and a year of audit retention.
Yes. Growth can be paid on-chain in $A (Vaulta blockchain) tokens instead of by card. Transfer the quoted amount with the memo shown at checkout and your account is set up automatically once the transfer is final.
Signed API requests, IP allowlists, business verification (KYB — checking a company and its owners rather than an individual), enhanced identity checks, a tamper-evident compliance export, a custom service-level agreement, and a data processing agreement. Data is stored in a single documented region; per-customer data residency is not offered today.
So the account can be reached — password resets, fraud notices, compliance mail. A code in an inbox or SMS proves control of that channel, not who the person is. KYC is still the only step that creates or promotes a Person. A stolen inbox cannot become an identity claim.
Provisional means the chain account exists and can do limited, sponsored activity. After a clean verification and bind, co-signature limits lift and the account is fully the user’s. Your app reads that status instead of running its own approval workflow.
No. Growth is $99 per month for the Identity Inc. platform only: verified contacts, sponsored accounts, bind, sanctions screening hooks, abuse limits, and audit export. Live ID checks are billed separately, per check, by the verification provider (Shufti Pro in production) — not included in the $99.
Same identity engine, different checkout. Blocksfinity’s identity page is for a person creating a free wallet account. identityinc.io is for a company that wants the API inside its own product. A person should not buy the Identity Inc. Growth product; a product team should not use the Blocksfinity consumer signup as their integration.
Still unclear on a term? We keep a plain-English glossary of every acronym on this site.