Show only what a service needs
Selective disclosure through sealed claims in your vault.
Step 4 of 5
One fact, not your file
Instead of handing a service your whole profile, you store individual claims in your vault — residency, an age band, a contact address — each sealed with a SHA-256 integrity hash that is verified on every read.
A service asks for residency; it learns one fact. It cannot see your other claims, your photo, or your record.
Delegation with limits
You grant another Xity wallet scoped, time-limited read access — identity:read for 24 hours, for example — and grants can expire rather than persist forever. Scopes are a closed allowlist; administrative scopes cannot be self-granted.
