I’m building a product
Integrate on the sandbox first (free test verifications, simulated chain, bi_test_ keys), then take production traffic on Builder or Growth. Marketing checkout issues production keys.
Start on the sandboxIdentity Inc.
Identity Inc. checks a government ID and a selfie before it creates a sponsored blockchain account. The photos stay with the verification provider. You get a signed result tied to that one account, plus an audit trail you can export.
For wallets, fintechs, marketplaces, and banks. Free to build on — $99/mo when you go live. Need a personal blockchain account instead? Create one on Blocksfinity.
This site is for teams adding identity to an app. If you just need a free personal blockchain account, that flow lives on Blocksfinity.
Integrate on the sandbox first (free test verifications, simulated chain, bi_test_ keys), then take production traffic on Builder or Growth. Marketing checkout issues production keys.
Start on the sandboxVerify your identity, choose a name, and keep your keys. The $99 platform fee is for apps, not for people.
Continue on BlocksfinityIf your app creates accounts or moves money, you have to know who the person is before you sponsor the account. Most teams still pick one of these.
Option 1
Anyone can open a funded account before you know who they are. Free tiers get farmed, and you find out at the first withdrawal.
Option 2
The vendor says the document looks real. You still have to store the answer, stop it being reused, screen sanctions, and prove the record a year later.
Option 3
The images land in your storage. The breach, the encryption, and the regulator's questions are now yours.
Identity Inc. stays out of those traps: verify the person, create the account, and bind the result so it cannot be moved.
Identity is checked first: a government ID and a selfie, with no code inside that check. The sponsored account comes after approval. You store no identity documents at any point.
Before an account exists, they photograph a government ID and take a selfie. That check does not include an email or phone code.
For developers: Person-first KYC, document and face. Default organizations refuse a free account until this is approved. Documents stay with the provider (live: Shufti Pro).
After approval, they choose an account name. We create and fund a blockchain account. The private key stays on their device.
For developers: One-time create token from KYC status, then sponsored account creation. The sandbox chain is simulated. Production is live Vaulta.
Email and phone codes are optional and separate. A code proves the channel works. It never creates a verified person.
For developers: Contact proofs are sealed at rest. Confirming a code never promotes a Person. The sandbox does not require them.
The user signs a one-time challenge on their own device. That is what makes verified status impossible to sell, share, or reuse somewhere else.
For developers: The signature binds the person to the account and issues a signed credential you can verify yourself.
Until unlock, the account is provisional: sponsored fees and tighter limits. After a clean bind, unlock hands it to the user.
For developers: Your app calls unlock, then reads one lifecycle field. A second unlock does nothing.
Screening keeps running in the background, and every decision is written to a log that can be exported and proven unaltered when someone asks.
For developers: Sanctions and politically-exposed-person flags, ongoing monitoring hooks, and a hash-chained audit export.
Because a verification provider answers one question, once: is this document real, and does the face match? Everything after that answer is yours to build. That everything-after is the product. In production the document check runs on Shufti Pro.
| The job | On your own | With Identity Inc. |
|---|---|---|
| Checking that an ID document is genuine | Your identity provider does this well. So do we — we call the same kind of provider. | The same check, through Shufti Pro in production. This part is not the hard part. |
| Holding the passport photo and the selfie | They land in your storage, and the breach risk, the encryption, and the audit scope are now yours. | They stay with the verification provider. You receive a signed result and a fingerprint of the document — never the document. |
| Tying a verification to one account | You write the logic yourself, and nothing stops the same approval being reused on another account. | The user signs with the private key on their own device, so a verification belongs to exactly one account and cannot be transferred. |
| Proving it a year later | You go digging through database rows and application logs, and hope nobody edited them. | One export, cryptographically chained, so you can show an auditor that no record was altered or removed. |
| Sanctions and watchlist screening | A second vendor, a second integration, and a scheduled job you have to keep alive. | Screened when the person verifies and re-screened over time, with flags on the record and a freeze switch for your compliance team. |
| Launching a second product | Your users verify all over again, and you integrate all over again. | One verified identity works across every app you run, with separate keys and separate policy per app. |
| Fake accounts and repeat fraudsters | Rate limits you invent, tune, and maintain yourself. | Signup velocity limits, shared-device clustering, and access that only widens after a clean verification. |
| Time to first working flow | Weeks of integration, then permanent maintenance. | An afternoon with the API. Free while you build, $99 a month once you are live. |
We are not the company that inspects the passport. Shufti Pro does that in production. We are the layer that turns that answer into something you can rely on, reuse, and prove.
The rule is usually the same — verify the person before money moves. What changes is the moment it applies.
Verify the person before the sponsored wallet account is created. They hold their own keys. Read account status before a withdrawal or a fiat on-ramp.
Onboard, screen against sanctions lists, and keep evidence your regulator will accept — without building a document vault or a screening pipeline in-house.
Verify the people who receive money, such as sellers, drivers, and earners, before their payout account is created.
Sits alongside your core systems: signed requests, IP allowlists, company verification for business customers, a service-level agreement, and a data processing agreement.
Fewer accounts you cannot name, less fraud, and a smaller compliance problem, from one integration.
Default organizations refuse a sponsored account until identity is approved. A new user does not start with a funded account and a promise to verify later.
Passport photos and selfies stay with the verification provider. You keep a signed result instead — a much smaller thing to secure, and a much smaller thing to explain after an incident.
Sanctions screening, an exportable audit trail that can be proven unaltered, retention rules, and a freeze switch — included, rather than six months of your roadmap.
One integration serves every product you run, each with its own key and its own policy. Launch the second app without making your users start over.
Every verified person is screened against sanctions and politically-exposed-person lists, then re-screened over time — with no ID documents kept on your side.
Everyone who verifies is checked against sanctions lists and politically-exposed-person lists — people whose public position makes them higher risk to serve.
Lists change, so people are re-checked afterwards. None of it requires you to collect or store their documents again.
Your compliance team can suspend an account in one click, with the evidence attached to the record for whoever reviews it next.
Signup limits, shared-device detection, and access that only widens after verification — so nobody farms a thousand accounts out of your free tier.
Caps per network address, per device, and per day, so free accounts cannot be created in bulk.
Accounts created from the same device or key are clustered together, which is how one person running hundreds of accounts becomes visible.
Limits only widen after a real verification and a clean risk score. New accounts never start with full access.
One integration covers every app you run — wallet, marketplace, or core banking. Build free today, go live for $99 a month.
The questions we get on every first call.
It verifies a person with a government ID and a selfie, creates a sponsored blockchain account only after that approval, and binds the result to that account with a signature from their own device, so you never store the passport photo or the selfie.
You stop sponsoring accounts for people you have not identified, and you stop being the company that holds passport images. You also get sanctions screening, a tamper-evident audit trail, and abuse limits without building them yourself.
A KYC (Know Your Customer) provider answers one question, once: is this document genuine, and does the face match? Everything after that is yours to build: storing the answer, tying it to a specific account so it cannot be reused, proving it to an auditor a year later, re-checking the person against sanctions lists, and stopping one individual from opening five hundred accounts. Identity Inc. is that layer. In production the document check runs on Shufti Pro, and the documents stay there.
One server-side integration. Start person-first KYC, wait for approval, create the account with the one-time token, bind, then unlock. Your app never handles identity documents or secret keys in the browser.
No. Every approved person gets a blockchain account we create and fund. That is what makes the verification permanent and non-transferable. Your app never has to think about chain mechanics. If you are already building on Vaulta (Antelope), you get direct access to the same accounts.
Not by Identity Inc., and not by you. Photos of IDs and selfies stay with the identity verification provider that captured them. Identity Inc. keeps only the outcome, a reference number, and a fingerprint (hash) of each document — enough to prove a check happened, not enough to leak someone's passport.
After the check passes, the user signs a one-time challenge with the private key on their own device. That signature is what ties the verification to one specific account, and it is recorded in a tamper-evident log. A verification that was not signed by the account holder is not accepted.
Yes. Use the sandbox at sandbox.identityinc.io for free test verifications against the real provider and a simulated chain. Builder is the free platform tier on production (identity checks there are billed by your verification provider). Growth is $99 per month and raises the limits: 10,000 verifications a month, 5,000 sponsored accounts a day, 600 requests a minute, and a year of audit retention.
Yes. Growth can be paid on-chain in $A (Vaulta blockchain) tokens instead of by card. Transfer the quoted amount with the memo shown at checkout and your account is set up automatically once the transfer is final.
Signed API requests, IP allowlists, business verification (KYB — checking a company and its owners rather than an individual), enhanced identity checks, a tamper-evident compliance export, a custom service-level agreement, and a data processing agreement. Data is stored in a single documented region; per-customer data residency is not offered today.
So the account can be reached — password resets, fraud notices, compliance mail. A code in an inbox or SMS proves control of that channel, not who the person is. KYC is still the only step that creates or promotes a Person. A stolen inbox cannot become an identity claim.
Provisional means the chain account exists and can do limited, sponsored activity. After a clean verification and bind, co-signature limits lift and the account is fully the user’s. Your app reads that status instead of running its own approval workflow.
No. Growth is $99 per month for the Identity Inc. platform only: verified contacts, sponsored accounts, bind, sanctions screening hooks, abuse limits, and audit export. Live ID checks are billed separately, per check, by the verification provider (Shufti Pro in production) — not included in the $99.
Same identity engine, different checkout. Blocksfinity’s identity page is for a person creating a free wallet account. identityinc.io is for a company that wants the API inside its own product. A person should not buy the Identity Inc. Growth product; a product team should not use the Blocksfinity consumer signup as their integration.
Still unclear on a term? We keep a plain-English glossary of every acronym on this site.