MOLTPASS
Moltpass is an experimental, privacy-focused framework for users and verifiers. It leverages open standards-based cryptography to enable the definition, issuance, and verification of earned holder-bound credentials.
In 2026, I wrote about combining Verifiable Credentials with Privacy Pass architecture to deliver blinded badges, tickets, and passes. I developed and contributed Bonded Trust, an open-source plugin to ensure that earned credentials can't be freely exploited.
This analogy, "A Touchstone is to Gold as Bonded Trust is to Identity," explains my interest in Bonded Trust and Earned, Holder-bound Credentials.
In ancient times, gold was the currency. An assayer's touchstone was used to produce evidence that a metal contained the specific precious element.
In modern times, data is the currency. A cryptographic touchstone is used to commit to a proof that a web session contained the specific precious fact.
The ancient touchstone produced a streak on a rock. The modern touchstone commits to a cryptographic proof. Both of these mechanisms produce a trust anchor. The trust anchor is what carries the authority for a fact to be presented credibly.
Why this matters
Let's pivot and talk about data brokers and intermediaries, where centralized identity data is the product. For them, various complex processes are involved in collecting personal identity data and establishing and maintaining business reputation. Their reputation is a price multiplier on the identity data.
Moltpass puts the data back with the people it describes. It is based on a person's earned identity and skips past third party control of these facts.
Picture a house hunter who wants to prove that they have sufficient funds in their account. This can happen with a consumer verification request to a bank, or via a financial data intermediary like Plaid today. The consumer verification request skips the intermediary but takes a long time (7-10 days) to process.
The promise behind Moltpass is that the house hunter can prove sufficient funds by presenting an electronically notarized transcript of their own SSL session with their own bank. By leveraging TLSN to verify the integrity and authenticity of a web session between a user and a server, the house hunter doesn't need to ask for permission from the bank or use a data broker. When the data that they already have access to includes a proof, it doesn't need to be permissioned or repackaged. It's always with its owners and the data intermediary is superflous.
The TLSN commitment can be relied upon in a variety of ways: digital wallets, tokens, etc. Pluggability means that any format the verifier accepts can be used to carry the proof from the house hunter to a relying party, who can check it. The commitment becomes much more useful when the data is portable and can be shown to a verifier.
Earned identity can only be validated through real actions and achievements. Moltpass enables defining, issuing, and verifying the real actions and achievements that are worth validating.
Signed, A Moltpass Dev
Questions and Answers