Anonymous age verification with passkey-powered encryption
Details
- External ID
- 49361478
- Source
- HN
- Company
- —
- Product
- Anonymous age verification with passkey-powered encryption
- Website domain
- loginwithone.com
- Launched
- Aug. 19, 2026
- Cohort
- —
- Upvotes
- 45
- Upvotes percentile
- 0.8508064516129032
- Tags
- —
- Fetched at
- Sept. 10, 2026, 5:32 a.m.
- Updated at
- Sept. 10, 2026, 5:32 a.m.
Description
This project has been kicking around in my head since I first heard about the webauthn PRF extension in early 2024. I've slowly chipped away at it since, and finally got things to a shareable state over the summer thanks to a very fun parental leave. Headed back to work tomorrow, so I figure there's no time like the present.tldr: A client-held encryption key derived during passkey authentication encrypts all sensitive user data prior to persistence so that only the user is able to decrypt and reuse that data on their device. This allows short-lived, privacy-preserving age proofs to be issued to requesting applications (18+, no PII shared) without requiring users to re-upload their documents. The SSO user experience is built on top of the OAuth 2.0 Authorization Code Flow.https://loginwithone.com - demo video + high-level architecture + FAQI also made the parody demo apps from the video public if anyone wants to play around with the user experience:https://demo.brainrot.loginwithone.com https://demo.dgnrt.loginwithone.com https://demo.kirby.loginwithone.comI suspect most will choose to pass on the ID stage for now (no offense taken, doing so is low reward in this context) but if you navigate to https://app.loginwithone.com after onboarding you can demonstrate the passkey-powered encryption on your email via the lock/unlock button.Very open to feedback and happy to answer any questions! I plan to pull the client-side encryption functionality into an open-source typescript library for general use, so any thoughts or suggestions on what you’d like to see out of that interface would be supremely useful. Thanks all,Michael
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Horizontal
- Function
- Compliance & governance
- Audience
- B2B
- AI stance
- Not AI
- Project type
- Commercial product
- Normalized one-liner
- age verification with passkey encryption
- Manually corrected
- False
Could you build this?
Partial The client-side WebAuthn PRF integration is doable, but handling cryptographic zero-knowledge or privacy-preserving identity verification against real government IDs requires specialized verification pipelines.
What it would actually take: The stack involves client-side WebAuthn utilizing the `prf` extension for symmetric key derivation (HKDF) to encrypt/decrypt payloads locally, coupled with an identity verification service (e.g., OCR on government IDs with liveness detection) or ZK-SNARK/mDL (mobile driver's license) proofs. The hard challenge is legal compliance, fraud mitigation, and proving claims (age > 18) without the backend ever seeing or storing plaintext PII.
Discussion
20 comments analyzed.
Competitors mentioned: Parental device filters/child-locked devices, National electronic ID systems, Google account age verification
Concerns raised: Users will abandon service for overseas alternatives rather than comply with verification, Government could use transaction logs to track which sites users visit, Identity data seen in plaintext during initial verification creates security risk, Passkey sharing/reuse not prevented - younger relatives or AI agents could use same credential, Doesn't actually solve child safety without device-level enforcement
Feature requests: Zero-knowledge proofs for age verification without revealing identity, Privacy Pass protocol for anonymous login tokens, Device-bound verification via HTTP headers instead of identity upload, Optional credential reissue from previous verified documents, Open source server-side code with verifiable enclave attestation
Competitors
Other products that read as similar to this one — 99 launches clear the similarity bar, closest 8 shown.
Attention rank: #13 of 100 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 293 days after the earliest competitor.
- Open Passkey · hn · 2026-04-19 · 10 upvotes · similarity 0.51
- Voice Age Verification · hn · 2026-06-16 · 8 upvotes · similarity 0.50
- Age-PHP: a PHP implementation of age encryption (post-quantum) · hn · 2026-04-11 · 6 upvotes · similarity 0.46
- Git-agecrypt · hn · 2026-04-27 · 7 upvotes · similarity 0.44
- CipherStash Stack · hn · 2026-05-21 · 17 upvotes · similarity 0.44
- Minimal NIST/OWASP-compliant auth implementation for Cloudflare Workers · hn · 2026-02-09 · 33 upvotes · similarity 0.43
- Bramble · hn · 2026-07-02 · 153 upvotes · similarity 0.41
- Uruky (EU-based Kagi alternative) now has Image Search and URL Rewrites · hn · 2026-06-04 · 236 upvotes · similarity 0.41
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.