Built for AI search, retrieval, and training
The identity-tech knowledge base for AI systems and human operators.
ID Tech Learning Center turns the identity technology industry into a public, machine-readable corpus: structured vendor records, technology primers, glossary terms, and continuously updated data cards, all backed by a browsable interface for human users.
For AI
Datasets, APIs, crawl guidance, and machine-readable access for AI systems.
Vendors
Browse structured vendor profiles and company intelligence.
Technologies
Learn the core concepts behind biometric and digital-ID systems.
Glossary
Ground sector terminology with concise, reusable definitions.
Latest digest
ID Tech Digest – September 17, 2026
Welcome to ID Tech’s digest of identity industry news. Here’s what you need to know about the world of digital identity and biometrics today:
Hush Finds Hardcoded Secrets in Public AI Tool Configurations
Cybersecurity firm Hush Security discovered that 12 percent of credential slots across roughly 82,000 public Model Context Protocol (MCP) configuration files contained hardcoded secrets exposing AI coding tool credentials, leaving sensitive infrastructure tokens visible in open repositories. Analyzing files associated with platforms such as Claude Code, Cursor, Visual Studio Code, Windsurf, Gemini, OpenAI Codex, and JetBrains, the study revealed that 55 percent of exposed credentials lacked standard vendor token patterns, 53 percent granted broad organizational or workspace access, and 80 percent carried no expiration dates. Across 7,681 tracked configuration histories, 1,394 secrets remained in active codebases while 243 had been removed from current versions but remained exposed in earlier Git commits, prompting recommendations for variable expansion, short-lived workload identities, and active secret rotation in alignment with updated NIST identity guidelines.
World Money Adds Biometric Proof-of-Human Rewards to Finance App
Tools for Humanity has launched World Money across more than 150 countries, introducing a self-custody digital asset finance application that connects cross-border transfers and decentralized finance with World ID biometric proof-of-human credentials. Integrated with Bridge virtual accounts and Stripe onramps supporting Apple Pay, the mobile platform enables cross-border stablecoin payments across eight currencies and incorporates a promotional boost on Morpho decentralized lending products for users who verify their biometric uniqueness via an Orb capture camera. Building on World ID 4.0 account-based credential architectures that feature key rotation and cross-device recovery, the app links cryptographic human-in-the-loop validation directly to financial products without requiring Orb scans for basic transfer and portfolio functions.
Westpac Gains New Zealand Accreditation for Digital Bank Account Credentials
Westpac has achieved official accreditation under New Zealand’s Digital Identity Services Trust Framework, becoming the nation’s first financial institution authorized to issue digital bank account credentials directly to the Govt.nz mobile wallet. Powered by credential infrastructure from Mattr, the service enables commercial clients using Westpac One Business to generate an encrypted, 72-hour credential via online banking and SMS verification, allowing verified financial details to be shared through verification channels like NZ Verify without relying on manual PDF bank statements. Joining earlier identity-matching accreditations held by NEC, the deployment establishes a foundational verifiable credential pipeline ahead of the bank’s planned retail expansion across its broader Westpac One consumer base.
iProov Publishes Experimental Protocol for Human Approval of AI Agent Actions
Biometric identity verification provider iProov has released an experimental open specification titled the Human Approval and Presence Specification (HAPS), designed to provide verifiable proof that a genuine person authorized a sensitive action proposed by an autonomous AI agent. Published under the Apache 2.0 open-source license with test vectors and a Rust reference architecture, the protocol pauses automated agent workflows to generate a signed consent credential containing cryptographic challenges, audience restrictions, expiration timestamps, and single-use nonces to prevent replay attacks across systems using OAuth, OpenID Connect, and WebAuthn. Designed to be agnostic toward underlying biometric capture systems while compatible with iProov’s facial liveness engine, the draft specification addresses emerging governance demands for accountable human-in-the-loop oversight across enterprise agentic tools.
Thailand Plans Verifiable Credential Trusted List and Wallet Pilots for 2027
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans to launch regulatory oversight and pilot deployments for verifiable credential trusted lists and digital wallets in 2027, establishing national standards for issuance, storage, and selective attribute presentation. The initiative will introduce an official VC Trusted List alongside mobile document wallets that allow citizens to verify attributes—such as academic credentials and government benefits eligibility—without exposing full national ID cards or generating redundant paper records. Expanding upon a baseline reference architecture developed with 17 public and private stakeholders that tested digital university transcripts, the program establishes interoperable technical standards and anti-revocation mechanisms separate from existing domestic identity tools like the Tang Rat social benefits app.
Malaysia Begins Issuing New MyKad With Restricted Biometric QR Verification
Malaysia’s National Registration Department (JPN) has officially commenced issuance of a newly redesigned national identity card, integrating restricted biometric QR verification alongside physical anti-counterfeiting features such as a transparent security window. Manufactured by NexG subsidiary Datasonic Technologies, the upgraded card omits legacy Touch ‘n Go transit payment chips and incorporates an encrypted QR code restricted strictly to official law enforcement agencies for electronic Know Your Customer checks against government biometric databases. While JPN clarified that citizen subsidy eligibility remains safely managed via backend agency databases rather than physical card storage, the design accommodates future commercial verification for approved banks and telecommunications operators alongside an optional digital citizen wallet.
iMTC Selects SEALSQ Security Chip for Fingerprint Medical Mouse
Taiwanese computer peripheral manufacturer iMTC Technology has selected SEALSQ’s QVault TPM183 cryptographic chip to power a fingerprint-recognition medical mouse engineered for shared clinical workstations and healthcare IT terminals. Designed to integrate directly into Windows Hello and Windows Enhanced Sign-in Security architectures, the device provides hospital clinicians and nursing staff with seamless biometric login that protects electronic medical records without altering daily input workflows. The hardware platform spans four distinct configurations—including the flagship iM-FRM-2608QS offering dedicated microcontroller support for FIDO2 passkey standards—anchored by SEALSQ’s Trusted Platform Module 2.0 hardware root of trust and a dedicated migration roadmap toward post-quantum cryptographic algorithms.
Insolvency Service Secures First Companies House Identity-Verification Convictions
The UK Insolvency Service has secured its first criminal convictions under the Economic Crime and Corporate Transparency Act 2023, fining three corporate directors at City of London Magistrates’ Court for Companies House identity verification violations. The enforcement action penalized Jill White and Modinat Banjo for executing corporate filings and signing accounts while unverified, while Marc Dillon was convicted and fined £307 alongside legal costs for failing to take reasonable steps to prevent an unverified co-director from conducting board business despite having completed his own identity proofing. The rulings reinforce strict compliance expectations surrounding Companies House digital verification rules tied to GOV.UK One Login, underscoring that corporate officers bear affirmative legal duties to ensure all active directors complete mandatory identity verification checks.
Poland Opens mObywatel Europa Sandbox for Digital Identity Wallet Integrations
Poland’s Ministry of Digital Affairs and the Central Information Technology Centre have launched a public development sandbox to support organizational testing for the mObywatel Europa digital identity wallet, facilitating preliminary integrations ahead of full European Digital Identity Wallet compliance under eIDAS 2.0. The test environment provides commercial relying parties across banking, insurance, telecommunications, and healthcare with a prototype mobile application, simulated citizen identity datasets, and a web-based attribute verifier to test selective disclosure of identity credentials and driving entitlements. Building upon Poland’s participation in large-scale EU cross-border pilots like POTENTIAL and APTITUDE—where national teams lead the technical architecture for mobile vehicle registrations—the sandbox accelerates domestic readiness for cross-border digital identity verification.
Somalia and Pakistan Set Digital Identity Cooperation Priorities
The National Identification and Registration Authority of Somalia and Pakistan’s National Database and Registration Authority (NADRA) have formalized a bilateral cooperation matrix establishing joint priorities for digital identity systems and financial inclusion following a ten-day technical mission organized by the United Nations Development Programme. Led by NIRA Director General Abdiwali Ali Abdulle, the Somali delegation reviewed Pakistan’s foundational identity registries, Lahore’s e-Khidmat public service centers, Benazir Income Support Programme disbursements, and the State Bank of Pakistan’s Raast instant payment and shared electronic KYC platforms. The resulting partnership framework focuses on secure national data exchanges, legal identity expansion, and digital social welfare delivery, drawing upon lessons from Pakistan’s registration outreach alongside Somalia’s extensive mobile money adoption.
–
By the ID Tech Editorial Team
Machine-readable access
Public datasets for AI ingestion
Vendor dataset
JSONLStructured identity-tech vendor and association records for retrieval, indexing, and training pipelines.
Technology dataset
JSONLTechnology primers with summaries, descriptions, references, FAQ content, and provenance.
Glossary dataset
JSONLDefined terms and related concepts for grounding identity-tech language and terminology.
Data Cards dataset
JSONLDate-stamped news cards that keep vendor and technology knowledge fresh for AI ingestion and retrieval.
