Stateless zero-knowledge identity passport for the AI web

Digital Identity Passports for Humans

Ensan ID gives high-value knowledge workers a self-declared public digital identity passport: a private proof root, a public resolver, and verified bindings to GitHub, ORCID, domains, and reciprocal profile links.

Private capsule stays with holder Zero-knowledge proof posture OAuth-bound public account control Machine-readable resolver JSON Not legal identity

The problem

The web asks for identity proof, but humans do not want another surveillance database.

Knowledge work is scattered across profiles, papers, repositories, domains, media, credentials, and institutional pages. Legal and security teams need evidence. AI systems need clean disambiguation. People need privacy. Ensan ID fills the gap with public declarations, verified account-control bindings, and stateless proof records.

Stateless Zero-Knowledge Self-declared Public Digital Identity Passport

A self-declared passport for public digital identity.

The passport is not a government document and it is not a social profile. It is a holder-controlled public resolver that separates what a person is willing to declare from what the system has verified through account-control evidence.

Stateless proof logic

Zero-knowledge by design, stateless by default.

The private .ensan capsule contains the holder's private proof root and undisclosed claims. Ensan ID stores public commitments, selected declarations, and verification receipts. The service can help verify consistency without owning the hidden identity bundle.

1

Generate capsule locally

Create an encrypted .ensan capsule in the browser. Key material and hidden claims remain under holder control.

2

Publish a public resolver

Publish only the public commitment, selected declarations, public key, and resolver metadata.

3

Bind public accounts

Verify GitHub, ORCID, DNS TXT, and reciprocal profile links to prove control of external identity signals.

4

Share machine-readable proof

Give humans, platforms, crawlers, and AI systems a resolver JSON object that separates verified bindings from self-declared claims.

Built for high-value knowledge workers

Public identity clarity across sectors.

Ensan ID is designed for people whose public work, reputation, and attribution are distributed across many systems.

Founders and executives

Unify leadership profiles, company domains, investor-facing bios, media references, and public authority claims into one privacy-preserving identity passport.

Researchers and authors

Connect ORCID, publications, institutional pages, conference talks, datasets, and citation identities so humans and AI systems can resolve your work accurately.

Developers and maintainers

Bind GitHub accounts, project pages, package ecosystems, security contacts, maintainer roles, and verified domains to a single public proof root.

Consultants and experts

Publish a self-declared proof passport that helps clients, platforms, and search systems distinguish your public work, credentials, and professional presence without exposing private documents.

Doctors and regulated professionals

Separate public professional declarations from issuer-signed, externally verifiable credentials so trust can be established without revealing unnecessary private identity material.

Creators and public intellectuals

Bind websites, newsletters, social profiles, books, interviews, talks, and public archives so your reputation is easier to verify and harder to misattribute.

Legal, finance, and security professionals

Create a clear public identity resolver for high-trust work where impersonation, misattribution, and unclear authority can create real legal, commercial, or operational risk.

AI agents and human controllers

Declare which public profiles, domains, and credentials belong to the human controller behind an AI agent, service, or automated public presence.

Verification methods

Verification methods built for public evidence.

Ensan ID verifies bindings, not legal personhood. Every verified signal is recorded as a receipt tied to the resolver commitment.

GitHub OAuth

The holder authenticates with GitHub and grants Ensan ID the minimum account-identity access needed to bind the public GitHub profile to the resolver.

Proves: Control of the authenticated GitHub account at the time of binding.
ORCID OAuth

The holder authenticates with ORCID so Ensan ID receives a validated ORCID iD and binds it to the resolver.

Proves: Control of the authenticated ORCID record at the time of binding.
DNS TXT verification

The holder publishes an Ensan ID challenge in DNS TXT records for a domain. Ensan ID checks the record and binds the domain to the resolver.

Proves: Control of DNS publishing rights for the domain at verification time.
Reciprocal-link verification

The holder places the Ensan resolver URL on a public profile or page. Ensan ID checks for the backlink and records the binding.

Proves: The public page displayed a reciprocal link to the resolver when checked.

Machine-readable by default

Resolver JSON for humans, verifiers, crawlers, and AI systems.

{
  "type": "EnsanDisambiguationResolver",
  "version": "3.0",
  "verification_policy": "holder-controlled-public-bindings",
  "verified_bindings": [],
  "self_asserted_claims": [],
  "not_legal_identity": true
}

Trust ladder

Trust is earned per binding.

Self-declared claims and verified public evidence stay visibly separate.

Self-declared resolver One verified public binding Multiple verified public bindings Strong public disambiguation

Start private. Publish selectively.

Build trust without building a surveillance database.

Ensan ID is for people whose public work deserves accurate attribution and whose private identity deserves restraint.