ZOREAL Identify
Alternatives to itsme
itsme is the Belgian mobile identity app operated by Belgian Mobile ID: a person enrols with the Belgian eID card and a card reader or through a partner bank, then identifies, logs in, confirms transactions and signs at more than 800 companies and platforms, under an eID scheme notified under eIDAS at assurance level High and, since 1 June 2026, in the Netherlands. ZOREAL Identify is a "Continue with ZOREAL" button on standard OpenID Connect, backed by the ZOREAL ID credential, that returns a pairwise pseudonymous identifier for a human verified against a government document chip, with the assurance of each login stated in the token. This page sets the two side by side: what anchors each identity, what each discloses to the relying party, where each is available, and how each is priced.
Information last reviewed 10 September 2026. Compared: itsme identification and authentication (login and identity sharing) with ZOREAL Identify. itsme’s qualified signature overlaps ZOREAL Sign and is noted only; itsme confirmation, data and document exchange, and qualification are out of scope.
Where ZOREAL Identify and itsme differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
Notified scheme, or own hierarchy
itsme is listed by the European Commission as "Belgian eID Scheme FAS / Itsme®", notified at assurance level "High" on 18 December 2019, and its authentication page states "eIDAS-certified: Level of Assurance (LoA) 'High'". ZOREAL issues its credential under its own certificate hierarchy, two roots (ECDSA P-384 and ML-DSA-87) with two holder certificates per verified document, holds no eIDAS level and is not a notified scheme.
Identity disclosed, or pseudonym by default
itsme identification shares verified identity data as its primary function: the person confirms sharing their verified identity data and the encrypted information transfers to the business. ZOREAL’s ID token carries no personal data, a pairwise pseudonym per sector plus the assurance block, with name, birthdate, document fields and email served only from userinfo to a confidential client with a verified domain after the person consents on the phone, and age returned as yes-or-no thresholds.
Where the document comes from
An itsme account is created "With your eID card and card reader" or "Via your bank" (BNPPF, Belfius, KBC, ING, Hello Bank or Fintro), in Belgium and, from 1 June 2026, the Netherlands, where itsme states "iDIN will be fully phased out by the end of 2027." ZOREAL enrols any supported chip document read by the phone over NFC and verified against the issuing country’s certificates from the ICAO master list, with no country base published.
Side by side
Comparison of ZOREAL Identify and itsme, based on public materials reviewed on 10 September 2026.
| Attribute | ZOREAL Identify | itsme |
|---|---|---|
| How the identity is bound | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | Enrolment binds the app to a person through the Belgian eID card and a card reader, or through the person’s bank (BNPPF, Belfius, KBC, ING, Hello Bank, Fintro); the app then identifies, authenticates, confirms and signs at partner services. For identification, the person confirms sharing their verified identity data, read from official ID documents (eID cards, passports, residence permits via NFC), and the encrypted information transfers to the business (Get started; Identification service). |
| What the login proves | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | That the person holds an itsme account bound at enrolment to a Belgian eID card or to a bank’s identified customer, under a scheme notified at High; identification returns verified identity data from the official document, authentication returns a "one-click login". The exact attribute set and identifier format are on the developer portal, which is not among the public materials we reviewed (Identification service; Authentication service). |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | "eIDAS-certified: Level of Assurance (LoA) 'High'" (Authentication service); the European Commission’s overview lists "Belgian eID Scheme FAS / Itsme®" at "High", notified "18 Dec 2019". |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | Belgian Mobile ID SA/NV issues the itsme account, bound at enrolment to the Belgian eID card and reader or to a partner bank, under the Belgian eID scheme notified under eIDAS (Get started; European Commission overview). |
| Identity disclosed | The ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when. One ZOREAL ID serves every service: a returning person at a consented sector approves on their phone without a new capture, or silently when the relying party asks for it; the identifier is stable within the relying party’s registered sector and different at unrelated sectors, so the credential is reused without being linkable across services | Yes at identification, with the person’s consent: verified identity data from the official document; a login for authentication. Whether the identifier is the same at every relying party is not stated in the public materials we reviewed (Identification service; Authentication service). |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | Free for the holder: itsme is described to consumers as a "free digital key" (Why itsme, itsme-id.com, September 2026). Enrolment needs a Belgian eID card and a card reader, or an account at one of the partner banks (Get started). |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | No published figures as of September 2026. Identification and authentication are priced as "gradually decreasing bracketed pricing" where "The price brackets that apply depend on the number of Active Users per Project", by request through the sales form on the product pages (Identification service; Authentication service). Through Signicat, itsme carries setup, subscription and transaction fees with figures in the Signicat Dashboard (Signicat pricing). |
| Coverage and relying parties | Holders of a supported chip document enrolled in the ZOREAL ID app; ZOREAL states no count of enrolled holders or relying parties. ZOREAL Meet runs on Identify as a production relying party since 2026-09-10. | "8 million+ users"; "over 80% of adults use itsme to identify themselves online" in Belgium; "Over one million identification checks are carried out daily"; live in the Netherlands since 1 June 2026; "available from more than 800 companies and platforms"; offered through Signicat and ForgeRock as identity brokers (Business page; Netherlands launch post; Why itsme; partner pages). |
| Certifications and signature | Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. ZOREAL asserts no eIDAS level and is not a notified scheme; ZOREAL Identify is not a legal signature. | eIDAS notification at High (European Commission overview). ISO or SOC attestations, and OpenID Connect or SAML support on itsme’s own API, are not stated in the public materials we reviewed. Qualified signature is one of itsme’s six services (Business page). |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what itsme offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and itsme agree
Both put a government document at the root of the identity and a phone-bound credential on top of it: itsme through the Belgian eID card at enrolment and NFC reads of eID cards, passports and residence permits for identification, ZOREAL through the chip read over NFC at enrolment. Both are free for the person holding the credential: itsme is a "free digital key", and the ZOREAL ID app is always free for the person from enrolment to recovery. Both are reused at many relying parties from one enrolment.
Both show the person what will be shared before it is shared. itsme has the person confirm sharing their verified identity data; ZOREAL’s consent screen names the relying party and every requested claim, and the person approves on the phone. Both reach relying parties through brokers as well as directly: itsme through Signicat and ForgeRock, ZOREAL through any authentication platform that consumes a standard OpenID Connect provider. Neither treats a login as a legal signature: itsme offers a separate qualified signature service, and ZOREAL Identify asserts none.
What differs is the anchor and the default. itsme is a scheme notified under eIDAS at assurance level High, enrolled with a Belgian eID card or a Belgian bank, covering Belgium and the Netherlands, and identification discloses the person; ZOREAL issues under its own hierarchy with no eIDAS level, enrols any supported chip document, and returns a pairwise pseudonym with the assurance of the login, disclosing attributes only on consent.
ZOREAL Identify may fit you if
- Your users hold chip documents from many countries rather than a Belgian eID card or a Belgian bank account
- You want a pairwise pseudonym by default, with name, birthdate and document fields released only on request and consent
- You want the assurance of each login stated in the token (a fresh liveness capture, a hardware-key approval, or a remembered session)
- You want the pricing structure published: Tier A logins free and unlimited, with a charge only on a Tier B login where identity disclosure is requested
itsme may fit you if
- Your users are in Belgium, where itsme states over 80 percent of adults already use it to identify online
- You need an eIDAS-notified identity at assurance level High for regulated onboarding, or a qualified signature from the same app
- You are replacing iDIN in the Netherlands before its stated phase-out by the end of 2027
- You already integrate through Signicat or ForgeRock, where itsme is offered as an identity method
Other alternatives to itsme
35 more vendors compared under ZOREAL Identify, from their own public materials.
- ID.meID.me Wallet and ID.me Identity Gateway
ID.me’s digital identity wallet: verify once to NIST 800-63-3 IAL2 with a government ID and selfie, then sign in across relying parties through OpenID Connect or SAML.
- Pricing
- No published price list as of September 2026; organisations use the Work with ID.me contact form. No consumer fee is stated on the pages read.
- Assurance
- NIST 800-63-3 IAL2 identity proofing and AAL2 authentication, Kantara-approved (Identity Gateway). Evidence is a government ID plus selfie, remote, by video or in person.
- Reuse
- Yes. The wallet presents the same verified identity to any relying party; ID.me states nearly 90 million identities verified to IAL2/AAL2.
- World IDWorld ID (Proof of Human, Document and Selfie Check credentials, IDKit)
World ID: a proof-of-human credential from an Orb iris scan or an NFC passport, presented as a zero-knowledge proof with a per-app nullifier and no personal data.
- Pricing
- Free for end users; no fee schedule for applications published as of September 2026, though the World Foundation stated in April 2025 that applications will be charged.
- Assurance
- Orb credential: one per human, iris-based. Document credential: one World ID per government document via NFC. Selfie Check: medium assurance, no strict one-person guarantee. No name or legal identity is asserted.
- Reuse
- Yes. One World ID is used at any integrating app; the nullifier is stable per person per action. Nearly 18 million verified humans stated in April 2026.
- Sign in with GoogleSign in with Google (Google Identity Services)
Google’s account login for websites and apps: a button, One Tap, and an OpenID Connect ID token carrying the Google Account ID, email, name and picture.
- Pricing
- No fee stated in Google’s developer terms as of September 2026; usage beyond documented limits may carry additional terms or charges.
- Assurance
- Proves control of a Google Account; the token flags whether Google verified the email address. No statement about the person behind the account.
- Reuse
- The same Google Account ID is presented to every relying party; a person may hold several accounts.
- Facebook LoginFacebook Login (including Limited Login on iOS)
Meta’s account login for apps and websites: a login dialog returning an app-scoped user ID, name, picture and, if granted, email.
- Pricing
- No fee stated in the Meta Platform Terms as of September 2026; the terms say free is not guaranteed.
- Assurance
- Proves control of a Facebook account and returns the profile’s name and picture. No document check, liveness or email-verified flag is stated.
- Reuse
- An app-scoped user ID per app; a person may hold more than one account.
- Sign in with AppleSign in with Apple (native, Sign in with Apple JS and the REST API)
Apple’s account login for apps and websites: a button backed by the Apple Account’s two-factor authentication, with a one-time name and email share and an optional relay email.
- Pricing
- No separate fee stated; requires Apple Developer Program membership at 99 USD per membership year, as listed on developer.apple.com in September 2026.
- Assurance
- Proves control of an Apple Account and returns a three-valued real user status signal. No document check or liveness is stated.
- Reuse
- The same Apple Account is used across apps; Apple’s pages do not state a uniqueness guarantee per person.
- Microsoft Entra IDMicrosoft identity platform: Microsoft account sign-in, Microsoft Entra External ID and Microsoft Entra ID
Microsoft’s identity platform: consumer Microsoft account and Entra work-account sign-in, plus Entra External ID for customer identity with social and enterprise federation.
- Pricing
- External ID is free for the first 50,000 monthly active users, then per-MAU meters listed at $0.03 (Basic) and $0.01625 (Core) in Microsoft’s retail price list; Entra ID P1 is $7.00 per user per month paid yearly, as listed in September 2026.
- Assurance
- Proves control of a Microsoft or Entra account, with a pairwise subject per application. No document check or liveness is stated for sign-in.
- Reuse
- Microsoft accounts and Entra accounts are reused across applications; Verified ID lets organisations issue reusable verifiable credentials to Microsoft Authenticator.
Common questions
How we compared
This comparison is based on publicly available information from itsme’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- itsme, Business homepage: 8 million+ users, six services, legal entity Read 2026-09-10
- itsme, Why itsme, easy to use: free digital key, 800+ companies and platforms Read 2026-09-10
- itsme, Get started: eID card and reader or via bank, banks listed Read 2026-09-10
- itsme, Identification service: bracketed pricing, NFC documents, data flow Read 2026-09-10
- itsme, Authentication service: bracketed pricing, LoA High, one-click login Read 2026-09-10
- itsme, Launch in the Netherlands and replacement of iDIN (1 June 2026) Read 2026-09-10
- itsme, New partner ForgeRock (25 October 2022) Read 2026-09-10
- European Commission, Overview of pre-notified and notified eID schemes under eIDAS: Belgium entries Read 2026-09-10
- Signicat, itsme identity method Read 2026-09-10
- Signicat, Pricing: setup, subscription and transaction fees Read 2026-09-10
- ZOREAL pricing (our own published claims) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by itsme. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.