Back

EUDI Wallet vs proof of personhood

One proves who you are and that a claim about you is true. The other proves you are one person and not a hundred. Using either for the other's job goes badly.

Two different questions

The European Digital Identity Wallet and a proof of personhood system are routinely compared as though they compete. They do not, because they answer different questions, and almost every argument about which is better turns out to be an argument about which question mattered.

The wallet answers: who is this person, and is this claim about them true? A member state stands behind the answer. Proof of personhood answers: is this one human being, and have I seen them before? Nobody stands behind the answer in the legal sense, and in exchange the answer does not require knowing who the person is.

What the wallet proves

Person identification data authenticated at a high level of assurance, plus attributes attested by whoever is authoritative for them: a licence from the licensing authority, a diploma from the university, a company role from the register. The value comes from the issuer being the source of truth, and from a chain of supervision behind that issuer.

It is also more private than it sounds from the outside. Selective disclosure means a wallet can prove you are over eighteen without handing over a date of birth, and a relying party has to declare which attributes it intends to request when it registers, which puts a limit on what it can ask for in the first place.

What it does not give you is a cheap uniqueness check. A relying party that only needs to know two accounts are not the same person, and asks for identity attributes to find out, is collecting more than it needs and taking on the obligations that come with holding it.

What proof of personhood proves

That the holder is a distinct human, and that this system has not issued the same standing to them twice. Not their name, not their age, not their entitlement to anything. In this project the credential carries a personhood score reflecting how many attestations of what kind were completed, so a verifier can set its own bar rather than accept a single yes.

The absence of identity is the point, not a limitation waiting to be fixed. A forum that wants one account per person, an airdrop that wants to not pay a bot farm, a rate limit that should follow a human rather than an IP address: none of those need a name, and a system that supplies one anyway has created a liability for everyone involved.

The trade is real and worth stating. Nobody is accountable for the answer. There is no supervisory body, no trusted list, no legal presumption. If the issuance process is fooled, the recourse is whatever the verifier built for itself.

Where each one is the wrong tool

Using the wallet as a sybil gate is disproportionate, and the regulation's own registration step makes that visible: you have to say what attributes you are asking for and why. “To check they are not two people” is a poor answer when a cheaper instrument exists.

Using proof of personhood for anything that needs legal effect is worse, because it looks like it works. A non-qualified attestation carries whatever the verifier decides it carries, which is fine for a rate limit and useless in a dispute. The longer version of that argument, including why qualified status is not something an open issuer can reach, is in a separate post.

Most systems need both, wired to different decisions. If you are working out which obligations the wallet actually puts on you and when, the eIDAS 2.0 timeline is the shortest route to the dates.

Get your personhood credential

Verify through the Gateway and receive a DID, a verifiable credential and a personhood token. No personal data is retained.

Stay updated.