MOLTPASS

The Moltpass is an experimental, privacy-focused framework for users and verifiers. It leverages open-standards based cryptography to enable the definition, issuance, and verification of earned holder-bound credentials.


In 2026, I wrote about combining Verifiable Credentials with Privacy Pass architecture to deliver blinded badges, tickets, and passes. I developed and contributed Bonded Trust, an open-source plugin to ensure that earned credentials can't be freely exploited.


This analogy, "A Touchstone is to Gold as Bonded Trust is to Identity," explains my interest in Bonded Trust and Earned, Holder-bound Credentials.

In ancient times, gold was the currency. An assayer's touchstone was used to produce evidence that a metal contained the specific raw element.

In modern times, data is the currency. A cryptographic touchstone is used to commit to a proof that a web session contained the specific raw fact.

In ancient times, a touchstone produced a mark on a rock as evidence. The modern touchstone commits to a cryptographic proof. These are both trust anchors. The trust anchor must have enough evidence of authority to present the raw element or fact with credibility.


Why this matters

Let's pivot and talk about data brokerages, where centralized identity data is the product. For a data broker, various complex processes are involved in collecting personal identity data and establishing or maintaining business reputation. The broker's reputation is a price multiplier on identity data.

Moltpass puts the data back with the people it describes. It is based on a person's earned identity. You or I may disclose age without giving away name and address. Disclosure should always be up to you and me.

Picture a house hunter who wants to prove that they have sufficient funds in their account. This can happen with a consumer verification request to a bank, or via a financial data aggregator like Plaid today.

The promise behind Moltpass is that the house hunter can prove sufficient funds by presenting an electronically notarized transcript of their own SSL session with their own bank. TLSN verifies the integrity and authenticity of web session data between a user and a server so the house hunter doesn't need to ask for permission from the bank or use a data broker. When the data that they already have access to includes a proof, it doesn't need to be permissioned or repackaged. It's always with its owners. The data aggregator becomes obsolete.

The TLSN commitment can be relied upon in a variety of ways: digital wallets, tokens, etc. Pluggability means that any format the verifier accepts can be used to carry the proof from the house hunter to a relying party, who can check it. The commitment becomes much more useful when the data can be shown to a verifier.

Earned identity can only be validated through real actions and achievements. Moltpass enables defining, issuing, and verifying the real actions and achievements that are worth validating.


Signed, A Moltpass Dev

Questions and Answers
Moltpass.dev — provable facts about me