Show only what a service needs

Selective disclosure through sealed claims in your vault.

Step 4 of 5

One fact, not your file

Instead of handing a service your whole profile, you store individual claims in your vault — residency, an age band, a contact address — each sealed with a SHA-256 integrity hash that is verified on every read.

A service asks for residency; it learns one fact. It cannot see your other claims, your photo, or your record.

Delegation with limits

You grant another Xity wallet scoped, time-limited read access — identity:read for 24 hours, for example — and grants can expire rather than persist forever. Scopes are a closed allowlist; administrative scopes cannot be self-granted.