ZOREAL Identify
Alternatives to World ID
World ID is described by its documentation as a "privacy-preserving protocol that lets people prove they are real and unique online without sharing personal information": a credential from an Orb iris scan, an NFC government document or a selfie check, presented to an app as a zero-knowledge proof with a nullifier that is stable per person per action. ZOREAL Identify is a "Continue with ZOREAL" button on standard OpenID Connect, backed by the ZOREAL ID credential, that returns a pairwise pseudonymous identifier for a human verified against a government document chip, with the assurance of each login stated in the token and identity attributes only on request and consent. This page sets the two side by side: what each proves, what each returns, how each keeps the person unlinkable, and what each costs.
Information last reviewed 10 September 2026. Compared: World ID proofs used at sign-in or account creation (IDKit and the Developer Portal verify API) with ZOREAL Identify. World App, World Chain, the WLD token and Deep Face (the Zoom integration, covered under ZOREAL Meet) are out of scope.
Where ZOREAL Identify and World ID differ
The guarantee
ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. ZOREAL is the only solution in the world today that can give that guarantee.
Bare proof, or attributes on consent
World ID returns a proof and a nullifier and nothing else: there is "no need to enter your name, birthdate, address, or any other identifying information to use it", and the proofs are zero-knowledge, so the issuer cannot see where a proof was used. ZOREAL returns a signed OpenID Connect token from a provider that sees every login, with no personal data in the token by default, and serves age thresholds and nationality on the free tier and name, birthdate and document fields only to a confidential client with a verified domain after the person consents on the phone.
Iris, document, or document plus face
World ID’s Orb credential is a biometric uniqueness claim with no document, "each human can only have one PoH credential"; its Document credential binds one World ID to one ICAO 9303 document over NFC, with authentication "ranging from passive authentication (signature verification only) to Active Authentication"; Selfie Check (Beta) is "medium-assurance" and "does not provide a strict one-person-one-account guarantee". ZOREAL reads the chip over NFC, re-runs Passive Authentication against the ICAO master list on its own side, proves chip possession through Active Authentication where the document supports it, and face-matches a liveness capture 1:1 to the chip portrait.
Liveness at issuance, or each login
World ID’s pages state liveness at credential issuance (the Orb, the Selfie Check) and do not state a liveness claim per proof. ZOREAL’s ID token states per login how the human was authenticated, in acr and amr: a fresh liveness capture face-matched to the enrolled document, a registered hardware-key approval, or a remembered session, and a relying party that sets a live floor is denied rather than downgraded when it cannot be met.
Side by side
Comparison of ZOREAL Identify and World ID, based on public materials reviewed on 10 September 2026.
| Attribute | ZOREAL Identify | World ID |
|---|---|---|
| How the identity is bound | Enrolment, in the ZOREAL ID app: the document is photographed, its machine-readable zone read and its chip read over NFC. The server re-runs Passive Authentication against its own trust store built from the ICAO Public Key Directory, so the issuing country’s signature over the data is checked on ZOREAL’s side, and the chip proves possession of its private key. A liveness capture with presentation-attack detection is face-matched 1:1 against the chip portrait. The device key is generated in the phone’s hardware, its attestation is verified at registration, and every evidence call carries an app-integrity assertion. Each verified document yields two holder certificates over that key under ZOREAL’s two roots (ECDSA P-384 and ML-DSA-87), one pseudonymous and one carrying the legal name, valid until the document expires. Login: ZOREAL is the OpenID Provider. The holder approves on their phone, a stock OIDC library validates the ID token against ZOREAL’s JWKS, the relying party sets the assurance per request with acr_values, max_age and prompt, and a request that cannot meet its floor is denied, never downgraded. The subject is pairwise per sector, so one ZOREAL ID is reused at every service without being linkable across them; consent is remembered per sector and re-prompted on any new scope. | A person obtains a credential, an Orb iris scan (Proof of Human), an NFC read of an ICAO 9303 document (Document, "Availability varies by country", validity "Document expiry, max 10 years"), or a selfie check (Selfie Check, Beta), held in the World ID app or World App; at a relying party the app produces a zero-knowledge proof and a nullifier, and "The same person verifying the same action always produces the same nullifier". After Orb verification "the data is encrypted, sent to your phone and permanently deleted from the Orb" (World ID docs; credential pages; IDKit integration; world.org). |
| What is proven | Two halves. Proof that a real human is there: the ID token asserts this is one human (not one account, not one device), with the strength of that claim in a uniqueness field; that a government document chip was read and its authenticity verified, at the month given; and how this session was authenticated, in acr and amr, whether a live human was captured for this login, a registered device key was used, or a session was reused. And, when the relying party requests it and the person consents on the phone, the verified identity: name, birthdate and document details read from the chip, served from userinfo to a confidential client with a verified domain. The person sees every requested claim before approving, and the relying party receives only the scopes it was granted. It is not KYC, not a legal signature, not proof that the person consented freely, and not proof that the person is the one operating the browser. | That the person is a unique human (Orb), or holds a unique government document (Document), or passed a medium-assurance selfie check, for the requested action; no name, birthdate, address or legal identity is asserted. The integrator chooses which credential backs the proof, and "Your backend must check that the nullifier hasn’t been used before" (World ID docs; IDKit integration). |
| Guarantee | ZOREAL guarantees that the person is real, is not an AI, exists, and is linked to a government-issued ID. One hundred percent, not ninety-nine point nine. | Proof of Human: "each human can only have one PoH credential", the "highest-assurance credential issued under World ID". Document: "Each document can only be used with one World ID". Selfie Check (Beta): "does not provide a strict one-person-one-account guarantee" (credential pages). |
| Who issues the credential | ZOREAL is the issuer of the ID card: a reusable identity credential that logs in to other websites, with the person controlling the scopes each login discloses. | Credentials are issued at an Orb (Proof of Human), from an NFC document read (Document) or from a selfie check (Selfie Check, Beta) and held in the World ID app; the relying party registers an app in the Developer Portal and verifies proofs against the verify API (World ID docs; IDKit integration). |
| Attributes and identifier | The ID token carries no personal data, ever: a pairwise pseudonym per sector plus the assurance block. Name, birthdate, document fields and email are served only from userinfo, against a ten-minute single-audience access token with no refresh token, and only to a confidential client with a verified domain; a relying party that needs the data again asks the person again. Age is returned as registered yes-or-no thresholds, never an age or a birth year. The document portrait is a separately gated tier and is biometric data under GDPR Article 9 for the relying party that requests it. Consent is remembered per sector and re-prompted on any new scope or claim, and the consent screen shows only what ZOREAL verified about the relying party. ZOREAL, as the OpenID Provider, sees every login: which holder, which relying party, when. One ZOREAL ID serves every service: a returning person at a consented sector approves on their phone without a new capture, or silently when the relying party asks for it; the identifier is stable within the relying party’s registered sector and different at unrelated sectors, so the credential is reused without being linkable across services | None: a proof and a nullifier, "no need to enter your name, birthdate, address, or any other identifying information to use it". The nullifier is stable per person per action, so a returning person is recognised for that action without the app learning who they are (world.org; IDKit integration). |
| Cost to enrol | Enrolment in the ZOREAL ID app is always free for the person holding the identity: document scan, chip read and liveness enrollment, re-enrollment, recovery and revocation. Every Tier A login is free without limit on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality, with 1 client configuration on Free. Answering an identity request is always free for the person. | "Usage will remain free for end users" (Introducing World ID Fees, 30 April 2025; the page carries a notice that it is over 12 months old). |
| Cost per sign-in | Enrolment is free: "The ZOREAL ID app is always free for the person holding the identity, from enrollment to recovery", and "Document scan, chip read and liveness enrollment" is "Always free" on Free and Premium. Every Tier A login is free, without limit, on every plan: the pairwise identifier, the assurance block, age-threshold answers and nationality (openid, zoreal.age and zoreal.nationality, available to every registered client). Tier A logins are never charged. A charge applies only to a qualified Tier B login, where the relying party requests identity disclosure (the profile scopes, name, birthdate and document details, and email, which require a verified domain, a confidential client and client authentication), on Premium: "Identify · Identity disclosure", "Name, birth date and document details", "One charge for name, birth date or document details, even when several are returned"; "Identify · Fresh-liveness login", "Coming soon"; "Content and contract signing authorization", "Coming soon". Client configurations per website or app: 1 on Free, 10 on Premium; private-key JWT and mTLS client authentication on Premium. Premium is priced per user, monthly or yearly, with two months free on yearly billing; every organization member is a paid Premium seat; metered usage is charged separately. Enterprise: contact us. Answering an identity request is always free for the person. Current prices are on the ZOREAL price list at zoreal.com/pricing. ZOREAL Identify is the cheapest way to do KYC in the market: free to enrol, free to check, paid only for the higher disclosure tiers. | No fee schedule published as of September 2026. The World Foundation stated in April 2025 that "applications will be charged for using World ID services", with a credential fee set by each issuer and a protocol fee; no per-verification price appears in the developer documentation, the Developer Portal or the announcements we reviewed. |
| Integration | Standard OpenID Connect from the provider at id.zoreal.com (discovery, JWKS, token and userinfo endpoints); any stock OIDC library validates the token. One client library per platform: @zoreal/oauth2-react, @zoreal/oauth2-js and @zoreal/oauth2-react-native on npm for the front end, and backends for Node (@zoreal/oauth2-node), Ruby (zoreal-oauth2), Python (zoreal-oauth2), PHP (zoreal/oauth2), Go, Java (com.zoreal:oauth2) and .NET (Zoreal.OAuth2). The React package renders the button and drives the flow itself, with no hosted script and nothing to allowlist in a Content Security Policy. Registration is self-serve in the dashboard (Identify, Assets): redirect addresses, origins and permitted scopes, with domain verification; personal-data scopes require a verified domain and a confidential client. | IDKit React widget ("add proof of human to your app with one React widget"), JS, Swift and Kotlin SDKs, and verification against POST https://developer.world.org/api/v4/verify/{rp_id}, with app_id, rp_id and signing_key from the Developer Portal. A Sign in with World ID OpenID Connect path is not listed in the current documentation index we reviewed, and its former URL returns 404 (World ID docs; IDKit integration; llms.txt). |
| Reach and certifications | Organization-level, as zoreal.com lists them for Bynn Intelligence, Inc.: SOC 2 (attestation), PCI DSS (SAQ A), GDPR (data protection), ISO/IEC 27001:2022 (information security certification) and CSA STAR Level One (cloud security self-assessment). No Identify-specific certification or scheme recognition is stated on zoreal.com as of September 2026. ZOREAL states no count of enrolled holders or relying parties. | "Nearly 18 million verified humans across 160 countries" (17 April 2026); "more than 450 million uses of World ID globally", cumulative uses rather than unique users (9 June 2026); World ID for Enterprise integrations announced with Zoom and Docusign (17 April 2026). Compliance attestations and retention periods are not stated in the public materials we reviewed. |
Third-party details on this page reflect what each provider publicly stated on the review date shown above and may have changed since. Where a provider does not state something publicly, this page says so rather than assuming. Statements about what World ID offers reflect its public materials on the review date; absence of a feature from those materials does not mean it is unavailable. ZOREAL's current prices are on the ZOREAL price list.
Where ZOREAL Identify and World ID agree
Both are reusable and pseudonymous by default. Neither releases a name, birthdate or address unless the integrator asks: World ID never does, and ZOREAL only through gated scopes the person approves. Both give the relying party a stable identifier that recognises a returning person without linking them across services: World ID’s nullifier is stable per person per action, and ZOREAL’s subject is pairwise per relying-party sector. Both are free for the person holding the credential.
Both bind one identity to one government document over NFC and refuse duplicates at the issuer: "Each document can only be used with one World ID", and ZOREAL derives one subject per person per sector with the strength of the uniqueness claim stated in the token. Both state their assurance tiers explicitly instead of flattening them: World ID names three credentials and says which carries a strict one-person guarantee, and ZOREAL names the uniqueness basis and the acr value of every login. Neither asserts a legal signature, and neither is KYC.
What differs is what the token carries and who can see the login. World ID’s Orb credential is a document-free uniqueness claim, and its proofs are zero-knowledge, so the issuer cannot see where they are used; ZOREAL is an OpenID Provider that signs each token and sees every login, and in return can state verified attributes (age thresholds, nationality, and on consent name, birthdate and document fields) and the liveness of this particular session, which World ID’s proofs do not carry.
ZOREAL Identify may fit you if
- You need verified attributes with consent: age thresholds and nationality on the free tier, name, birthdate and document fields on Premium
- You want the assurance of each login stated in the token (a fresh liveness capture, a hardware-key approval, or a remembered session)
- You want a standard OpenID Connect provider that any stock library validates, with the relying party setting the assurance floor per request
- You want the pricing structure published: Tier A logins free and unlimited, with a charge only on a Tier B login where identity disclosure is requested
World ID may fit you if
- You need to know that a user is a unique human without collecting any identity attribute
- You want a document-free uniqueness credential (the Orb) for a consumer audience across 160 countries, per World in April 2026
- You want zero-knowledge proofs so the issuer cannot see where a proof was used
- You are integrating with Zoom or Docusign, where World ID for Enterprise integrations were announced in April 2026
Other alternatives to World ID
35 more vendors compared under ZOREAL Identify, from their own public materials.
- ID.meID.me Wallet and ID.me Identity Gateway
ID.me’s digital identity wallet: verify once to NIST 800-63-3 IAL2 with a government ID and selfie, then sign in across relying parties through OpenID Connect or SAML.
- Pricing
- No published price list as of September 2026; organisations use the Work with ID.me contact form. No consumer fee is stated on the pages read.
- Assurance
- NIST 800-63-3 IAL2 identity proofing and AAL2 authentication, Kantara-approved (Identity Gateway). Evidence is a government ID plus selfie, remote, by video or in person.
- Reuse
- Yes. The wallet presents the same verified identity to any relying party; ID.me states nearly 90 million identities verified to IAL2/AAL2.
- itsmeitsme identification and authentication
Belgium’s mobile identity app: identification, login, confirmation and qualified signature for 8 million+ users, enrolled with the Belgian eID card or through a partner bank, live in the Netherlands since June 2026.
- Pricing
- No published figures; bracketed pricing by active users per project, decreasing with volume, by request from itsme, as stated on itsme-id.com in September 2026. The app is free for the holder.
- Assurance
- eIDAS-notified scheme at assurance level High (18 December 2019); enrolment through the Belgian eID card and reader or a partner bank.
- Reuse
- Yes. One itsme account is used at more than 800 companies and platforms; identification shares verified data from the official document with consent.
- Sign in with GoogleSign in with Google (Google Identity Services)
Google’s account login for websites and apps: a button, One Tap, and an OpenID Connect ID token carrying the Google Account ID, email, name and picture.
- Pricing
- No fee stated in Google’s developer terms as of September 2026; usage beyond documented limits may carry additional terms or charges.
- Assurance
- Proves control of a Google Account; the token flags whether Google verified the email address. No statement about the person behind the account.
- Reuse
- The same Google Account ID is presented to every relying party; a person may hold several accounts.
- Facebook LoginFacebook Login (including Limited Login on iOS)
Meta’s account login for apps and websites: a login dialog returning an app-scoped user ID, name, picture and, if granted, email.
- Pricing
- No fee stated in the Meta Platform Terms as of September 2026; the terms say free is not guaranteed.
- Assurance
- Proves control of a Facebook account and returns the profile’s name and picture. No document check, liveness or email-verified flag is stated.
- Reuse
- An app-scoped user ID per app; a person may hold more than one account.
- Sign in with AppleSign in with Apple (native, Sign in with Apple JS and the REST API)
Apple’s account login for apps and websites: a button backed by the Apple Account’s two-factor authentication, with a one-time name and email share and an optional relay email.
- Pricing
- No separate fee stated; requires Apple Developer Program membership at 99 USD per membership year, as listed on developer.apple.com in September 2026.
- Assurance
- Proves control of an Apple Account and returns a three-valued real user status signal. No document check or liveness is stated.
- Reuse
- The same Apple Account is used across apps; Apple’s pages do not state a uniqueness guarantee per person.
- Microsoft Entra IDMicrosoft identity platform: Microsoft account sign-in, Microsoft Entra External ID and Microsoft Entra ID
Microsoft’s identity platform: consumer Microsoft account and Entra work-account sign-in, plus Entra External ID for customer identity with social and enterprise federation.
- Pricing
- External ID is free for the first 50,000 monthly active users, then per-MAU meters listed at $0.03 (Basic) and $0.01625 (Core) in Microsoft’s retail price list; Entra ID P1 is $7.00 per user per month paid yearly, as listed in September 2026.
- Assurance
- Proves control of a Microsoft or Entra account, with a pairwise subject per application. No document check or liveness is stated for sign-in.
- Reuse
- Microsoft accounts and Entra accounts are reused across applications; Verified ID lets organisations issue reusable verifiable credentials to Microsoft Authenticator.
Common questions
How we compared
This comparison is based on publicly available information from World ID’s official website, documentation, pricing and published materials, and on ZOREAL’s own published product pages and pricing, as reviewed on 10 September 2026. Features, pricing and availability may change at any time. Verify current details directly with each provider before deciding.
Nothing on this page is legal advice. Which electronic signature method satisfies which law, what level of identity assurance a regulation requires, and whether a content signature or provenance mark meets a given standard all depend on the jurisdiction and the regulator’s guidance. ZOREAL Sign asserts no legal effect for the signatures it records. Confirm your obligations with qualified counsel before choosing a method.
Sources
- World, World ID product page: anonymity, Orb data deletion Read 2026-09-10
- World, developer docs, World ID overview: protocol, credential types, IDKit Read 2026-09-10
- World, Proof of Human credential Read 2026-09-10
- World, Document credential (ICAO 9303) Read 2026-09-10
- World, Selfie Check (Beta) credential Read 2026-09-10
- World, IDKit integration: Developer Portal, verify API, nullifier Read 2026-09-10
- World, documentation index Read 2026-09-10
- World, The new World ID and the partners bringing proof of human to the internet (17 April 2026) Read 2026-09-10
- World, World ID for Enterprise: Zoom and Docusign (17 April 2026) Read 2026-09-10
- World, The Simple Plan and Phase 3 (9 June 2026) Read 2026-09-10
- World, Introducing World ID Fees (30 April 2025) Read 2026-09-10
- World Developer Portal landing page Read 2026-09-10
- ZOREAL pricing (our own published claims) Read 2026-09-11
- ZOREAL Identify product page Read 2026-09-11
ZOREAL is operated by Bynn Intelligence, Inc. and is not affiliated with, sponsored by, or endorsed by World ID. Third-party names and trademarks are the property of their respective owners and are used only to identify the products being compared.
See ZOREAL Identify for yourself.
A product walkthrough, pricing or volume terms, with the ZOREAL team.