The Proof-of-Human standard · PoHF v1.0

One open standard for proving a human did it.

The Proof-of-Human-Fulfillment (PoHF) credential: a signed token that a real, ID-verified, live human performed a specific action. Built on JWS, ES256 and JWKS, with a W3C Verifiable Credentials profile.

  • Any JWT library
  • No 5arz software
  • Trust no one
★ PoHFverified: true
ISShttps://5arz.comSUB_HASHno raw PIIALGES256
A credential card and the claims a PoHF seal carries.
ES256
P-256 signed JWT, verified via public JWKS — RFC 7515/7519
<1 ms
per-credential verification (p50 0.09 ms · p99 0.56 ms) — fast enough for payment-auth
W3C VC
Verifiable Credentials 2.0 profile — plugs into wallet and identity rails
The credential

What’s in a PoHF credential.

ClaimMeaning
issIssuer (e.g. https://5arz.com)
vctType: …/proof-of-human-fulfillment
verifiedMust be true — a real human did it
sub_hashHashed subject — no raw PII, ever
session_id · task_type · work_kindThe specific action attested
deviceDevice attestation + assurance tier (App Attest / Play Integrity / WebAuthn)
iat · exp · jtiIssued-at, expiry, unique id
cnfOptional holder key-binding (RFC 7800)
Verify it

No 5arz software. No trust required.

Local and offline. Measured p50 0.09 ms / p99 0.56 ms with cached keys — built for authorization decisions under 100 ms.

Try it in your browser
verify.js
import { jwtVerify, createRemoteJWKSet } from "jose";

const JWKS = createRemoteJWKSet(
  new URL("https://api.5arz.com/.well-known/jwks.json")
);

// throws if it isn't a valid, unexpired 5arz credential
const { payload } = await jwtVerify(token, JWKS);
// payload.verified === true, payload.device?.assurance, ...
Device assurance

Assurance tiers.

none

No device attestation bound — human + action only.

basic

Device-integrity token received and nonce-bound.

hardware

Full Apple App Attest / Google Play Integrity / WebAuthn verification. Require it for high-risk decisions.

FAQ

Questions, answered.

What is the proof-of-human standard?

The Proof-of-Human-Fulfillment (PoHF) credential is an open, cryptographically signed token (JWT, ES256/P-256) asserting that a real, ID-verified, live human performed a specific action. Anyone verifies it against a public JWKS with any standard library — no issuer software and no trust in the issuer required. It also has a W3C Verifiable Credentials profile.

How fast is verifying a PoHF credential?

Verification is local and offline. Measured per-credential verification with cached keys is about 0.09 ms median and 0.56 ms at p99, fast enough for transaction-time authorization decisions under 100 ms. Issuance is a separate one-time step.

Is PoHF compatible with W3C Verifiable Credentials?

Yes. The compact JWS is the wire format, and the spec defines an equivalent W3C Verifiable Credentials (Data Model 2.0) presentation with a ProofOfHumanFulfillment type, so it plugs into wallet and identity ecosystems.

Build on the standard.

The format is open and free to verify and implement. Issue your own on the Free plan — 1,000 seals a month, no card.