World has open-sourced ProveKit, a zero-knowledge proving toolkit that allows developers to build identity checks around facts such as age, citizenship, or possession of a valid document without requiring users to hand over the underlying personal data.
The release expands technology already used in World ID beyond World’s own applications. ProveKit entered early access in April and is now available to external developers, a World Foundation spokesperson said. Its central design choice is local proof generation: cryptographic proofs are created on a user’s smartphone or in a web browser, rather than by uploading sensitive identity information to a company-operated server.
That model places World’s identity technology into a more consequential debate over how businesses handle document scans. Cybersecurity journalist Brian Krebs reported this week that the FBI’s New Orleans field office is investigating Nexus, a dark web service allegedly offering scans of more than 153 million U.S. and Canadian driver’s licenses. Krebs wrote that the data appeared to originate from IDScan.net, an identity-verification company.
The reported exposure follows other large breaches involving identity records, including the theft of 10 million identification cards and nearly 579,000 medical records cited in the supplied material. Such incidents show the risks created when passports, driving licences, and other documents are retained as readable files in centralized corporate databases.
Proofs generated on the device
ProveKit is designed to let someone demonstrate a narrow claim without revealing their full identity document. A user could, for example, prove they are above a required age, are a resident of a particular country, or hold a government-issued credential. The service verifying that claim would receive a cryptographic proof rather than a full image of the passport or licence.
Zero-knowledge proofs are cryptographic methods that allow one party to show a statement is true while withholding the data used to establish it. In an identity setting, the approach could reduce the routine collection of document images for services that only need one attribute, such as whether a customer is old enough to access an age-restricted product.
According to World, ProveKit uses local proving rather than delegated proving, where personal data is sent to an outside service to calculate the proof. Keeping the calculation on a device means the source data is not transferred to a proving server, reducing the number of systems that could be targeted or mishandle it.
Damien Bloemen, head of blockchain at the World Foundation, argued in a post on X that identity documents should be authenticated with zero-knowledge proofs instead of being disclosed in full. The open-source release gives outside developers a chance to test whether that approach can work beyond World’s own ecosystem, including in consumer applications that currently rely on uploading document photographs.
NFC documents form the starting point
World ID credentials can locally store data read from NFC chip-enabled identity documents, according to the World Foundation spokesperson. NFC, or Near Field Communication, is the short-range wireless standard used by many modern passports and national identity cards. A smartphone placed near the document can read data from its embedded chip.
Those chips contain information digitally signed by the issuing authority. ProveKit can verify that signature and produce a proof from it inside a zero-knowledge circuit, World said. The company said this design keeps the document data inaccessible to the World Foundation, Tools for Humanity, and other third parties.
The distinction is practical for companies that need to verify a credential but do not need to hold a copy indefinitely. Car-rental firms, online platforms, and regulated financial services commonly collect identity documents for fraud prevention or compliance. A proving system would not erase every legal retention requirement, but it could allow some checks to be completed with less sensitive data flowing into corporate storage.
World said ProveKit has been in development for about two years. The toolkit supports Noir, a Rust-inspired programming language created by Aztec for zero-knowledge applications. World also said developers can add new provable claims without bundling each claim directly into an application, a structure intended to make the toolkit more flexible as document standards and use cases change.
Mobile performance and blockchain plans
World said the first version of ProveKit is production-ready and can operate on standard consumer hardware, including phones and browsers. Project benchmarks indicate that proof generation can take seconds on a typical smartphone and less than 30 seconds on a low-end device used in testing.
Proof creation time remains a major constraint for privacy-preserving identity tools. Systems that require specialist hardware or long processing times are poorly suited to a user standing at a checkout counter, accessing a website, or completing a time-sensitive account check. World’s device-level benchmarks suggest it is targeting these everyday cases, though real-world performance will vary by device, document type, and the complexity of the claim.
Version 1 focuses on off-chain verification by servers, computers, and mobile devices. World is developing ProveKit v2 with the aim of reducing proof sizes, processing times, and memory requirements while improving on-chain verification.
One option under review is support for Groth16, a zk-SNARK proving system widely used for efficient verification on blockchains. World said Groth16 support could enable verification on networks including World Chain, Ethereum, Base, and Solana. The earlier version of World ID used the Ethereum Foundation’s Semaphore protocol, which also uses Groth16.
The spokesperson said ProveKit targets 128-bit post-quantum security and does not require a trusted setup, a preliminary configuration process used by some zero-knowledge systems that can introduce additional security assumptions. World said known classical and quantum attacks should remain computationally infeasible at that security level.
Regulatory pressure remains unresolved
The release arrives while World’s biometric identity program continues to face regulatory scrutiny. Authorities in Spain, Kenya, Brazil, Indonesia, South Korea, Hong Kong, and the Philippines have examined aspects of the project, which uses Orb hardware to verify that a participant is a unique human. World said it continues to engage with regulators as it expands.
Open-sourcing ProveKit does not settle those disputes, particularly questions around biometric data collection, consent, and the treatment of identity information across different jurisdictions. It does give developers access to a technical model that seeks to minimize how much document data must be disclosed after a credential has been issued.
For World, the test now shifts from demonstrating that zero-knowledge identity checks can work inside World ID to proving that outside developers, businesses, and public-facing services can use them without adding friction or creating new trust dependencies.
Want deeper insight into privacy, KYC, and identity in crypto? Explore how Toobit protects your crypto identity today.
Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.
