The Proof-of-Human-Fulfillment (PoHF) credential: a signed token that a real, ID-verified, live human performed a specific action. Built on JWS, ES256 and JWKS, with a W3C Verifiable Credentials profile.
| Claim | Meaning |
|---|---|
iss | Issuer (e.g. https://5arz.com) |
vct | Type: …/proof-of-human-fulfillment |
verified | Must be true — a real human did it |
sub_hash | Hashed subject — no raw PII, ever |
session_id · task_type · work_kind | The specific action attested |
device | Device attestation + assurance tier (App Attest / Play Integrity / WebAuthn) |
iat · exp · jti | Issued-at, expiry, unique id |
cnf | Optional holder key-binding (RFC 7800) |
Local and offline. Measured p50 0.09 ms / p99 0.56 ms with cached keys — built for authorization decisions under 100 ms.
Try it in your browserimport { jwtVerify, createRemoteJWKSet } from "jose"; const JWKS = createRemoteJWKSet( new URL("https://api.5arz.com/.well-known/jwks.json") ); // throws if it isn't a valid, unexpired 5arz credential const { payload } = await jwtVerify(token, JWKS); // payload.verified === true, payload.device?.assurance, ...
No device attestation bound — human + action only.
Device-integrity token received and nonce-bound.
Full Apple App Attest / Google Play Integrity / WebAuthn verification. Require it for high-risk decisions.
The Proof-of-Human-Fulfillment (PoHF) credential is an open, cryptographically signed token (JWT, ES256/P-256) asserting that a real, ID-verified, live human performed a specific action. Anyone verifies it against a public JWKS with any standard library — no issuer software and no trust in the issuer required. It also has a W3C Verifiable Credentials profile.
Verification is local and offline. Measured per-credential verification with cached keys is about 0.09 ms median and 0.56 ms at p99, fast enough for transaction-time authorization decisions under 100 ms. Issuance is a separate one-time step.
Yes. The compact JWS is the wire format, and the spec defines an equivalent W3C Verifiable Credentials (Data Model 2.0) presentation with a ProofOfHumanFulfillment type, so it plugs into wallet and identity ecosystems.
The format is open and free to verify and implement. Issue your own on the Free plan — 1,000 seals a month, no card.