Identity Inc.

Verify the person. Then open the account.

Identity Inc. checks a government ID and a selfie before it creates a sponsored blockchain account. The photos stay with the verification provider. You get a signed result tied to that one account, plus an audit trail you can export.

  • ID and selfie first. No email or phone code inside that check
  • You never store a passport photo or a selfie
  • Sanctions screening and audit-ready proof, included

For wallets, fintechs, marketplaces, and banks. Free to build on — $99/mo when you go live. Need a personal blockchain account instead? Create one on Blocksfinity.

Identity Inc. logo

Two different jobs. Same engine.

This site is for teams adding identity to an app. If you just need a free personal blockchain account, that flow lives on Blocksfinity.

I’m building a product

Integrate on the sandbox first (free test verifications, simulated chain, bi_test_ keys), then take production traffic on Builder or Growth. Marketing checkout issues production keys.

Start on the sandbox

I need a free account

Verify your identity, choose a name, and keep your keys. The $99 platform fee is for apps, not for people.

Continue on Blocksfinity

Three ways this usually goes wrong

If your app creates accounts or moves money, you have to know who the person is before you sponsor the account. Most teams still pick one of these.

Option 1

Create the account first

Anyone can open a funded account before you know who they are. Free tiers get farmed, and you find out at the first withdrawal.

Option 2

Stop at the document check

The vendor says the document looks real. You still have to store the answer, stop it being reused, screen sanctions, and prove the record a year later.

Option 3

Hold the passport photos yourself

The images land in your storage. The breach, the encryption, and the regulator's questions are now yours.

Identity Inc. stays out of those traps: verify the person, create the account, and bind the result so it cannot be moved.

What your users actually experience

Identity is checked first: a government ID and a selfie, with no code inside that check. The sponsored account comes after approval. You store no identity documents at any point.

Step 1

They prove who they are

Before an account exists, they photograph a government ID and take a selfie. That check does not include an email or phone code.

For developers: Person-first KYC, document and face. Default organizations refuse a free account until this is approved. Documents stay with the provider (live: Shufti Pro).

Step 2

They pick a name and get an account

After approval, they choose an account name. We create and fund a blockchain account. The private key stays on their device.

For developers: One-time create token from KYC status, then sponsored account creation. The sandbox chain is simulated. Production is live Vaulta.

Step 3

They prove you can reach them, if you ask

Email and phone codes are optional and separate. A code proves the channel works. It never creates a verified person.

For developers: Contact proofs are sealed at rest. Confirming a code never promotes a Person. The sandbox does not require them.

Step 4

The result is locked to that account

The user signs a one-time challenge on their own device. That is what makes verified status impossible to sell, share, or reuse somewhere else.

For developers: The signature binds the person to the account and issues a signed credential you can verify yourself.

Step 5

The account becomes fully theirs

Until unlock, the account is provisional: sponsored fees and tighter limits. After a clean bind, unlock hands it to the user.

For developers: Your app calls unlock, then reads one lifecycle field. A second unlock does nothing.

Step 6

You stay covered afterwards

Screening keeps running in the background, and every decision is written to a log that can be exported and proven unaltered when someone asks.

For developers: Sanctions and politically-exposed-person flags, ongoing monitoring hooks, and a hash-chained audit export.

What your backend actually calls

  1. Step 1. Mint a sandbox bi_test_ key (sandbox checkout API), or a production bi_ key via Builder checkout.
  2. Step 2. Start person-first KYC, then create the sponsored account with the create token.
  3. Step 3. Handle the KYC webhook (or poll status); document + face — no OTP in KYC.
  4. Step 4. Bind the result to the account and read one status field.

“Why not just use a verification provider directly?”

Because a verification provider answers one question, once: is this document real, and does the face match? Everything after that answer is yours to build. That everything-after is the product. In production the document check runs on Shufti Pro.

What you have to build yourself versus what Identity Inc. includes
The jobOn your ownWith Identity Inc.
Checking that an ID document is genuineYour identity provider does this well. So do we — we call the same kind of provider.The same check, through Shufti Pro in production. This part is not the hard part.
Holding the passport photo and the selfieThey land in your storage, and the breach risk, the encryption, and the audit scope are now yours.They stay with the verification provider. You receive a signed result and a fingerprint of the document — never the document.
Tying a verification to one accountYou write the logic yourself, and nothing stops the same approval being reused on another account.The user signs with the private key on their own device, so a verification belongs to exactly one account and cannot be transferred.
Proving it a year laterYou go digging through database rows and application logs, and hope nobody edited them.One export, cryptographically chained, so you can show an auditor that no record was altered or removed.
Sanctions and watchlist screeningA second vendor, a second integration, and a scheduled job you have to keep alive.Screened when the person verifies and re-screened over time, with flags on the record and a freeze switch for your compliance team.
Launching a second productYour users verify all over again, and you integrate all over again.One verified identity works across every app you run, with separate keys and separate policy per app.
Fake accounts and repeat fraudstersRate limits you invent, tune, and maintain yourself.Signup velocity limits, shared-device clustering, and access that only widens after a clean verification.
Time to first working flowWeeks of integration, then permanent maintenance.An afternoon with the API. Free while you build, $99 a month once you are live.

We are not the company that inspects the passport. Shufti Pro does that in production. We are the layer that turns that answer into something you can rely on, reuse, and prove.

Built for teams who have to know who their users are

The rule is usually the same — verify the person before money moves. What changes is the moment it applies.

Crypto wallets and exchanges

Verify the person before the sponsored wallet account is created. They hold their own keys. Read account status before a withdrawal or a fiat on-ramp.

Fintech and neobanks

Onboard, screen against sanctions lists, and keep evidence your regulator will accept — without building a document vault or a screening pipeline in-house.

Marketplaces and gig platforms

Verify the people who receive money, such as sellers, drivers, and earners, before their payout account is created.

Banks and regulated institutions

Sits alongside your core systems: signed requests, IP allowlists, company verification for business customers, a service-level agreement, and a data processing agreement.

Why teams choose Identity Inc.

Fewer accounts you cannot name, less fraud, and a smaller compliance problem, from one integration.

No funded account before you know who they are

Default organizations refuse a sponsored account until identity is approved. A new user does not start with a funded account and a promise to verify later.

You never hold the documents

Passport photos and selfies stay with the verification provider. You keep a signed result instead — a much smaller thing to secure, and a much smaller thing to explain after an incident.

The compliance evidence is already there

Sanctions screening, an exportable audit trail that can be proven unaltered, retention rules, and a freeze switch — included, rather than six months of your roadmap.

Verify once, use across every app

One integration serves every product you run, each with its own key and its own policy. Launch the second app without making your users start over.

Sanctions and watchlist checks, handled

Every verified person is screened against sanctions and politically-exposed-person lists, then re-screened over time — with no ID documents kept on your side.

Sanctions and PEP lists

Everyone who verifies is checked against sanctions lists and politically-exposed-person lists — people whose public position makes them higher risk to serve.

Kept up to date

Lists change, so people are re-checked afterwards. None of it requires you to collect or store their documents again.

Freeze and escalate

Your compliance team can suspend an account in one click, with the evidence attached to the record for whoever reviews it next.

One real person, one account

Signup limits, shared-device detection, and access that only widens after verification — so nobody farms a thousand accounts out of your free tier.

Signup limits

Caps per network address, per device, and per day, so free accounts cannot be created in bulk.

Shared-device detection

Accounts created from the same device or key are clustered together, which is how one person running hundreds of accounts becomes visible.

Trust that has to be earned

Limits only widen after a real verification and a clean risk score. New accounts never start with full access.

Ship identity once. Use it everywhere.

One integration covers every app you run — wallet, marketplace, or core banking. Build free today, go live for $99 a month.

Straight answers

The questions we get on every first call.

In one sentence, what does Identity Inc. do?

It verifies a person with a government ID and a selfie, creates a sponsored blockchain account only after that approval, and binds the result to that account with a signature from their own device, so you never store the passport photo or the selfie.

What problem does it solve for my business?

You stop sponsoring accounts for people you have not identified, and you stop being the company that holds passport images. You also get sanctions screening, a tamper-evident audit trail, and abuse limits without building them yourself.

How is this different from using a KYC provider directly?

A KYC (Know Your Customer) provider answers one question, once: is this document genuine, and does the face match? Everything after that is yours to build: storing the answer, tying it to a specific account so it cannot be reused, proving it to an auditor a year later, re-checking the person against sanctions lists, and stopping one individual from opening five hundred accounts. Identity Inc. is that layer. In production the document check runs on Shufti Pro, and the documents stay there.

What do I actually have to build?

One server-side integration. Start person-first KYC, wait for approval, create the account with the one-time token, bind, then unlock. Your app never handles identity documents or secret keys in the browser.

Do I need to know anything about blockchain?

No. Every approved person gets a blockchain account we create and fund. That is what makes the verification permanent and non-transferable. Your app never has to think about chain mechanics. If you are already building on Vaulta (Antelope), you get direct access to the same accounts.

Where are identity documents stored?

Not by Identity Inc., and not by you. Photos of IDs and selfies stay with the identity verification provider that captured them. Identity Inc. keeps only the outcome, a reference number, and a fingerprint (hash) of each document — enough to prove a check happened, not enough to leak someone's passport.

What stops a verified user from sharing or selling their status?

After the check passes, the user signs a one-time challenge with the private key on their own device. That signature is what ties the verification to one specific account, and it is recorded in a tamper-evident log. A verification that was not signed by the account holder is not accepted.

Is there a free tier?

Yes. Use the sandbox at sandbox.identityinc.io for free test verifications against the real provider and a simulated chain. Builder is the free platform tier on production (identity checks there are billed by your verification provider). Growth is $99 per month and raises the limits: 10,000 verifications a month, 5,000 sponsored accounts a day, 600 requests a minute, and a year of audit retention.

Can I pay without a card?

Yes. Growth can be paid on-chain in $A (Vaulta blockchain) tokens instead of by card. Transfer the quoted amount with the memo shown at checkout and your account is set up automatically once the transfer is final.

What do larger institutions get?

Signed API requests, IP allowlists, business verification (KYB — checking a company and its owners rather than an individual), enhanced identity checks, a tamper-evident compliance export, a custom service-level agreement, and a data processing agreement. Data is stored in a single documented region; per-customer data residency is not offered today.

Why ask for email and phone if that is not identity?

So the account can be reached — password resets, fraud notices, compliance mail. A code in an inbox or SMS proves control of that channel, not who the person is. KYC is still the only step that creates or promotes a Person. A stolen inbox cannot become an identity claim.

What is a provisional account versus an unlocked one?

Provisional means the chain account exists and can do limited, sponsored activity. After a clean verification and bind, co-signature limits lift and the account is fully the user’s. Your app reads that status instead of running its own approval workflow.

Does the $99 Growth plan include ID checks?

No. Growth is $99 per month for the Identity Inc. platform only: verified contacts, sponsored accounts, bind, sanctions screening hooks, abuse limits, and audit export. Live ID checks are billed separately, per check, by the verification provider (Shufti Pro in production) — not included in the $99.

Is this the same as signing up on Blocksfinity?

Same identity engine, different checkout. Blocksfinity’s identity page is for a person creating a free wallet account. identityinc.io is for a company that wants the API inside its own product. A person should not buy the Identity Inc. Growth product; a product team should not use the Blocksfinity consumer signup as their integration.

Still unclear on a term? We keep a plain-English glossary of every acronym on this site.

Identity Inc. Verify the person. Then open the account.