Verify any ID. Issue
cryptographic credentials.
Authonex scans and verifies physical IDs with state-level precision, then issues W3C Verifiable Credentials with Ed25519 signatures. Present via 60-second rotating QR tokens that cannot be faked or screenshotted.
Free tier: 100 verifications/month · Vercel + Neon + Google Cloud KMS + Upstash
ALEX JOHNSON
VC-2026-8472
ALEX JOHNSON
VC-2026-8472
Built on infrastructure you trust
What is Authonex
The complete identity lifecycle —
from scan to cryptographic proof.
Authonex does two things no other platform does together: it verifies physical IDs with state-level precision (PDF417 decoding, AAMVA parsing, security feature checks), and it issues Verifiable Credentialswith Ed25519 cryptographic signatures. Every credential is presented via 60-second rotating QR tokens that cannot be faked, screenshotted, or replayed.
Scan
Upload or photograph any ID. PDF417 barcode decoded, 50+ AAMVA fields parsed instantly.
Verify
292-line validity matrix checks state specs, security features, expiry, and revocation. Risk scored 0-100.
Issue
W3C Verifiable Credential sealed with Ed25519 via Google Cloud KMS. Private key never touches our servers.
Present
60-second rotating QR tokens with Redis TTL and replay prevention. Each scan invalidates the token.
How It Works
Four phases. Zero Trust at every step.
From physical document to cryptographic proof — every step is auditable and tamper-evident.
Scan & Verify
User uploads or scans their physical ID. Authonex decodes the PDF417 barcode, parses 50+ AAMVA fields, and checks state-specific security features against official specifications.
PDF417 decoding + AAMVA parsing + 292-line validity matrix = deterministic verification.
Risk Assessment
Our risk engine analyzes IP frequency, device fingerprint reuse, request velocity, and known fraud patterns. Every request gets a 0-100 risk score before a decision is made.
Redis-backed real-time scoring with IP/fingerprint/velocity heuristics.
Issue Credential
Verified data is formatted into a W3C Verifiable Credential and sealed with an Ed25519 signature via Google Cloud KMS. The private key never touches our servers.
If even one byte changes, the signature breaks instantly upon verification.
Present & Re-Verify
The user presents a 60-second rotating QR token. A verifier scans it, checks the Ed25519 signature against our public key, and the token is invalidated — preventing replay.
Short-lived JWTs + Redis TTL + replay prevention = zero screenshot vulnerability.
Products
Everything from document scan to credential issuance
Nine tools that work together — or stand alone — to cover the complete identity lifecycle.
Document Verification
Upload any ID — driver's license, passport, state card. Our system decodes PDF417 barcodes, checks security features, and returns a detailed validity report in seconds.
Hard Copy Scanner
Point your camera at a physical document. Our scanner reads both sides, checks state-specific security features (holograms, microprint, UV ink), and confirms authenticity — like a trained inspector.
Risk Engine
Automatically detect fraudulent documents and suspicious submissions. IP frequency analysis, fingerprint reuse detection, request velocity tracking, and real-time threat scoring.
Verifiable Credential Issuer
Issue W3C-compliant Verifiable Credentials with Ed25519 cryptographic signatures via Google Cloud KMS. Not a visual render — a mathematically provable identity that cannot be faked.
Ephemeral QR Tokens
60-second rotating QR codes with Redis TTL and replay prevention. Each scan invalidates the token. Screenshot attacks are mathematically impossible.
Zero-Knowledge Proofs
Prove you are over 18 without revealing your birthdate. Verify identity without exposing your address. Selective disclosure returns a cryptographic TRUE/FALSE, not PII.
B2B Headless API
Integrate Authonex into your app with a few lines of code. $0.05 per verification. Third parties see only verified payloads — never raw document data.
Offline Verification (BLE)
Air-gapped identity verification via Bluetooth Low Energy. Works at traffic checkpoints, remote events, and network-congested venues. No cellular required.
Real-time Event Webhooks
Receive instant notifications for verification.completed, license.created, vc.issued, and more. HMAC-SHA256 signed with automatic retry delivery.
Detailed Reports
Every verification comes with
a full breakdown
You do not just get a "valid" or "invalid" result. Every check is listed with details — PDF417 decode, AAMVA compliance, security features, risk score, and revocation status. So you know exactly what was verified and why.
PDF417 barcode decoding
zxinggo library — 10MB limit, 500ms timeout, goroutine isolation
AAMVA field parsing
50+ fields extracted: name, DOB, address, restrictions, endorsements
State-specific security checks
Holograms, UV ink, microprint, watermarks — per state specs
Risk engine scoring
IP frequency, fingerprint reuse, request velocity — 0 to 100 scale
Revocation database check
Checked against state and federal revocation lists in real time
California Driver License
Issuing State: CA · Report generated just now
Document Format
Matches CA DMV specifications
PDF417 Barcode
Decoded via zxinggo — 50+ fields parsed
AAMVA Compliance
DL format version 01, correct DCS/DAA
Security Features
Hologram, UV ink, microprint detected
Expiration Date
Valid until 2028-03-15
Revocation Check
Not found in revocation database
Risk Score
Score: 12/100 — Low risk, no anomalies
Age Verification
Age 28 — Over 21 confirmed
Infrastructure Stack
Built for production, designed for
zero-trust verification
Frontend / Edge API
Vercel (Next.js)
Global edge network for sub-100ms response times
Relational State
Neon (PostgreSQL)
Serverless Postgres with branch-based development
Ephemeral Memory
Upstash (Redis)
Microsecond KV store for 60s token TTL + replay prevention
Hardware Security
Google Cloud KMS
Ed25519 signing in secure enclaves — keys never touch our servers
Who It's For
Identity tools for every stakeholder
Whether you are proving your own identity, verifying customers, or integrating into your platform.
Verify your ID once, prove it anywhere
Upload your driver's license or state ID. Get verified in seconds against official state specifications. Then get a cryptographically signed Verifiable Credential with a rotating QR code you can present anywhere.
Upload a photo of your ID — front and back accepted
PDF417 barcode decoded, 50+ fields parsed from AAMVA format
Verified against state security features — holograms, microprint, UV ink
Receive a W3C Verifiable Credential signed with Ed25519
Present via 60-second rotating QR code — impossible to screenshot
Prove you are over 21 without revealing your birthdate or address
Your Verification Flow: 1. Open app → Tap "Verify My ID" 2. Take photo of front → Take photo of back 3. PDF417 decoded → AAMVA parsed 4. State features checked → Risk scored 5. Result: ✓ VERIFIED (Trust: 0.95) Your Virtual ID: ┌─────────────────────┐ │ ░░▓▓▓▓▓▓▓▓▓▓▓░░ │ │ ░▓ AUTHONEX VC ▓░ │ │ ░▓ Ed25519 SIGNED▓░ │ │ ░▓ TTL: 47s ▓░ │ │ ░░▓▓▓▓▓▓▓▓▓▓▓░░ │ └─────────────────────┘ Scan to verify. Token expires in 60s. Replay protected. Zero screenshot risk.
Virtual IDs
Your identity, beautifully secured
Every verified credential becomes a stunning virtual ID — cryptographically signed, visually distinctive, and presented via 60-second rotating QR tokens.
ALEX JOHNSON
VC-2026-8472
Standard
Basic verified credential
ALEX JOHNSON
VC-2026-8472
Verified
Enhanced identity check
ALEX JOHNSON
VC-2026-8472
Gold
Premium credential tier
ALEX JOHNSON
VC-2026-8472
Platinum
Enterprise-grade identity
Use Cases
Real problems, real solutions
From nightlife to logistics — document verification and credential issuance that work anywhere.
Bars, Clubs & Nightlife
Age verification without touching IDs
Patrons scan their license and get a Verifiable Credential. They present a 60-second QR code at the door. Your staff scans it — instant age confirmation via ZKP proof. No physical ID handling, no privacy concerns.
2s
scan-to-verify time
0
PII exposed per scan
HR & Onboarding
I-9 compliance with cryptographic audit
New hires upload documents through your portal. Authonex verifies authenticity, checks security features, and generates a compliance-ready audit trail. Every verification is cryptographically signed and tamper-evident.
99.2%
accuracy rate
80%
faster than manual review
Logistics & Gig Economy
Time-bound access for drivers and contractors
Issue ephemeral access grants cryptographically bound to identity, delivery manifest, and geofence. Credentials auto-expire when the delivery window closes or the driver leaves the geofence.
100%
chain-of-custody accuracy
0
expired credential breaches
Financial Services & KYC
Compliance-grade identity verification
Verify customer identities at account opening, re-verify periodically, and flag suspicious changes. Full cryptographic audit trail for regulators. SOC 2 compliant infrastructure with Google Cloud KMS signing.
85%
reduction in onboarding time
SOC 2
compliant infrastructure
50
US states covered
Ed25519
Cryptographic signing
99.2%
Verification accuracy
60s
Ephemeral token TTL
Global Infrastructure
Built for worldwide trust
Authonex operates on a global edge network with sub-100ms response times across 6 continents. We support identity documents from every recognized nation and comply with international verification standards.
195+
Countries Supported
40+
Edge Locations Worldwide
99.99%
Global Uptime SLA
Trusted by organizations in every region
Supporting documents from all 195 UN-recognized nations + territories. Custom integrations available for enterprise.
Security Architecture
What makes us different
Document verification with state-level precision, cryptographic issuance, and zero-trust presentation.
State-level document verification
Every US state has different security features on their IDs. We check against official specifications — not a generic template. PDF417 decoded, AAMVA parsed, 50+ fields validated.
Real-time risk engine
IP frequency analysis, device fingerprint reuse detection, request velocity tracking. Every request scored 0-100. Redis-backed with sub-millisecond response times.
Ed25519 cryptographic signing
Every credential sealed with Ed25519 via Google Cloud KMS. If even one byte changes, the signature breaks. Verifiable by anyone with our public key.
60-second ephemeral tokens
Dynamic QR codes that expire in 60 seconds. Redis TTL + replay prevention. A screenshot of a QR code is useless — it is already expired by the time someone tries to use it.
Zero-knowledge selective disclosure
Prove you are over 21 without revealing your birthdate. The proof returns a cryptographic TRUE/FALSE boolean. No PII transmitted, no data stored.
B2B headless API
Integrate verification into any platform with a few lines of code. $0.05 per API ping. Third parties see only verified JSON payloads — never raw document data.
Verify a document. Issue a credential. Today.
Scan any ID with state-level precision. Get a cryptographically signed Verifiable Credential. Present it anywhere with a 60-second rotating QR code. Free tier includes 100 verifications per month.