
Yoti acts as a network facilitator enabling proof of age from certified* third-party providers to be stored securely on a user’s device using “Yoti Keys”. This leverages standard technologies such as passkeys to bind an anonymous age token directly to a user’s device, allowing the credential to be reused across different apps and websites without repeating the verification process.
This allows a relying party that needs to check a user’s age to send a request and set criteria for the credentials it will accept, such as the minimum age threshold (e.g., over 18), the specific verification method used, and how recently the check was performed. If the user consents by unlocking their passkey, the device shares the anonymous token. The response is returned in a standardized format, allowing the relying party to verify its authenticity and ensure it was generated by a trusted issuer.
Because the solution is double-blind, the relying party receives only a confirmation that the age condition is met, without ever learning the user’s identity or receiving personal data. Furthermore, the token issuer cannot see which specific service the user is accessing. Yoti’s network allows multiple certified Age Assurance Service Providers to mint and consume these tokens, creating an open marketplace where issuers can independently set the price for their token’s reuse.
Certification can include:
- internationally recognised standards such as (but not restricted to) ISO 27566, 27001, 9001
- levels of assurance for digital ID, IDV, PAD, IAD independently tested by NIST approved testing agencies
All age providers joining the network are required to be certified to ISO 27566 within 3 months of applying to join the network, to facilitate trust for relying parties and end users issued age tokens.
Age assurance providers do not pay to issue tokens, to encourage issuance to as many people as possible
For further information: https://www.yoti.com/business