Proof of personhood by XODE

Know it's a person.
Learn nothing else.

Xodian lets your app confirm that each user is one real human on a genuine phone. No selfies, no ID uploads, no personal data. Your app gets a signed, private credential, and each phone can produce only one per app.

Hardware-attested devices Pairwise, unlinkable IDs On-chain decision receipts

Why it matters

One phone. One person. One claim.

A farmer with fifty wallets looks like fifty users to you. Xodian ties each answer to the hardware key in one genuine phone, so the farm becomes one claimant again.

Without Xodian

Every wallet counts as a person. One phone farm drains the campaign.

0claims from one farm

With Xodian

Same phone, same person, same sub. The other 49 wallets resolve to one ID.

0claim from one farm

Illustration of the rule, not a measurement: Xodian returns the same pairwise ID for every wallet on one phone.

Built for

Anywhere one person should mean one account

Tokens going to a queue of people while robot boxes are held behind a barrier

Airdrops & rewards

Pay each person once. Fifty wallets on one phone still get one claim.

A game controller with one player badge and duplicate badges dissolving

Games

One account per player for ranked play, trials and starter bonuses.

A queue of people casting ballots into a glass box

Votes & communities

One person, one vote, without asking members who they are.

People walking through a glowing gateway while robots are filtered out before a vault

Fintech onboarding

Filter bots before KYC, so you only pay for full checks on real people.

How it works

About five seconds for the user

They scan, read what's shared, and confirm in omni. Your backend gets a credential it can verify offline.

Scan with omni×
Point at the code on Acme Airdrop
Xodian×
A

Acme Airdrop wants to confirm you're a real person

✓ acme.exampleRequires: Established
ACME AIRDROP WILL RECEIVE
✓ That you're a real person on a genuine phone
✓ A private ID only Acme can see
NEVER SHARED
🔒 Your name, phone number or face
🔒 Your wallet, balance and activity
Confirm
Decline
Xodian×

You're verified

Acme Airdrop now knows you're a real person, and nothing else.

◆ Established

Privacy by construction

We're careful about what you don't receive

Your users keep their privacy, and you don't take on the liability of storing data you never needed.

YOUR BACKEND RECEIVES · id_token✓ Verified human
{
  "iss": "https://xodian.xode.net",
  "aud": "rp_acme",
  "sub": "oid_9f3c1a…e07b",   // only you see this
  "human": true,
  "level": 2,
  "level_name": "established",
  "uniqueness": "new",
  "nonce": "claim-8812",
  "receipt": "1759651200-a1b2c3d4"
}
Name, face, ID documents omni never collects them in the first place
Phone number, device model Not even the platform: Android or iPhone
Wallet, balance, activity The address only if you ask and the user agrees
Links to other apps Each app gets a different ID for the same person

Assurance

Choose how strict to be

Set minLevel when you open a session. Below it you get rejected and nothing else, and omni tells the person privately how to qualify.

1
LEVEL 1 · DEVICE

A real person on a genuine phone

  • Wallet bound to a hardware key (StrongBox, TEE or Secure Enclave)
  • Passed Google Play Integrity or Apple App Attest, recently re-checked
  • Rejects emulators, rooted devices and modified builds
For sign-ups, trials and bot filtering
2
LEVEL 2 · ESTABLISHED

Level 1, plus a track record

  • Account at least 14 days old, active on at least 7 days
  • No device change in the last 30 days
  • Each fake identity needs its own phone, kept running for weeks
For airdrops, payouts and votes

Hardware keys

The phone signs with a key that cannot leave its secure chip, so a copied wallet seed is not enough.

Store attestation

Google and Apple vouch that the device and the app are genuine and unmodified.

Pairwise IDs

A different ID for every app, so partners can't join their data to track a person.

On-chain receipts

Every decision is anchored on XODE hourly, so anyone can check it wasn't changed afterwards.

Integrate

Three calls, no SDK lock-in

It's plain HTTPS and a standard JWT, so any language and any JOSE library will work.


    

Sandbox

Build the whole integration before you own a phone

Test keys work like live keys, except a simulator answers instead of a phone. Tokens verify with the same code and carry "test": true. Reject that flag in production.

1 · Get a test key

Free and instant. You can get up to 5 keys a day, and each key allows 500 sessions a day.

// Get a test key to begin. Every call you make appears here,
// with the exact request your server would send.

Live demo

Try it with your own phone

This runs against the production service. On the right is exactly what a partner's backend receives.

Verify yourself

Open omni on your phone, then scan the code. On mobile, the button opens omni directly.

💡You'll need omni from Google Play or the App Store, with your device registered. The demo asks for level 1.
// Waiting. Press "Verify with Xodian" to start.

API reference

Endpoints

Base URL is https://xodian.xode.net. Authenticate server calls with Authorization: Bearer osk_….

EndpointAuthPurpose
POST/v1/sessionssecretBody {scope, minLevel, reference}. Returns sessionId, url, deeplink, pollToken and expiresAt (5 min).
GET/v1/sessions/{id}secretStatus. Once approved, also idToken, sub and level.
GET/v1/sessions/{id}/status?t=pollTokenStatus only, safe to call from the browser. The widget uses this.
POST/v1/test/clientsnoneSelf-serve sandbox key: {name} → client id and secret.
POST/v1/test/sessions/{id}/simulatetest sessionAnswer a test session: approve, deny, reject or expire.
GET/v1/.well-known/jwks.jsonpublicSigning keys (ES256, selected by kid).
GET/sentinel/receipt/{receipt}publicMerkle proof that the decision was anchored on the XODE chain.

Session states

pending → approved | denied | rejected | expired. Each session can be used once.

Webhooks

session.* and grant.revoked events, signed with X-Omni-Signature: t=…,v1=HMAC_SHA256(secret, t.body).

Token checks

Verify the signature, then iss, aud, exp, and that nonce equals your reference. Use sub as the user key.

Uniqueness

new, returning (same person or same phone), or contested (this wallet moved onto a phone already used by someone else). Treat contested as a likely duplicate.

Questions

Before you integrate

Is this KYC?

No. Xodian proves that someone is one real person on a genuine phone. It never learns or shares who they are. Many teams use it before KYC, so they only pay for full identity checks on people who pass.

Do you collect biometrics or documents?

No. There are no selfies, no face scans and no ID uploads. The proof comes from the phone's hardware key and from Google Play Integrity or Apple App Attest.

What happens when someone gets a new phone?

They keep the same ID for your app, because the wallet carries it across. A wallet that moves onto a phone already used by someone else comes back marked contested, so you can decide how to treat it.

Can one person still farm with many phones?

Yes, one ID per genuine phone. Level 2 makes that expensive, because each phone has to be kept active for weeks. What Xodian removes is the cheap version: many wallets, emulators and modified apps on one device.

What does it cost?

Xodian is in early access for partners building on XODE. Test keys are free. For live keys and pricing, contact us.

Stop paying bots

Get a test key in seconds and finish your integration today. For live keys, tell us what you're protecting.