Four words of this section.
Whoever holds the secret and wants to convince: you, your phone, the supplier's system. →
Whoever needs to be convinced without learning the secret: the site, the bank, the auditor. →
The sentence being proved: "I am over 18", "my balance is above R$ 10,000", "I am on the list". Public, short and exact. →
The data that makes the statement true and never leaves where it is: the date of birth, the balance, which name on the list. →
Proving your age without showing your ID.
Since March 17, 2026, Brazil's Digital Statute for Children and Adolescents (Law 15.211/2025, known as ECA Digital) has been in force. Social networks, games, app stores and adult content services need reliable age verification; simple self-declaration ("I am an adult") no longer counts. And data collected for that purpose may only be used for it.
The obvious way to comply is to ask for the ID. It settles the age and hands over everything else: name, number, photo, address, exact date. Every site ends up keeping a copy of your ID, and every copy is a leak waiting to happen.
With a zero-knowledge proof, the ID stays on your phone. The issuing authority already signed your data once. The phone generates a proof that that signed data says you were born more than 18 years ago, and the site receives only that: a true sentence and the mathematical guarantee that it is true.
Everything, to learn one thing
- Full namehanded over
- ID numberhanded over
- Date of birthhanded over
- Photohanded over
- Parents and addresshanded over
- Over 18?yes
Only what it needed
- Full namestays on the phone
- ID numberstays on the phone
- Date of birthstays on the phone
- Photostays on the phone
- Parents and addressstays on the phone
- Over 18?yes, proved
This is not just theory: in 2025 the European Commission published a blueprint for an age verification app that uses exactly this kind of proof, being piloted in seven countries in 2026, and Google open-sourced the age proof it uses in its digital wallet. Details and sources in practical uses.
A sealed envelope, a challenge, an answer.
Every zero-knowledge proof, from the cave to the phone, has the same structure. The how it works page shows each step with real cryptography running in your browser.
Seal
The prover commits to the answer before seeing the question, like putting a note in a sealed envelope. After that, the content cannot be swapped without breaking the seal.
Challenge
The verifier picks a random question the prover had no way of predicting. In the cave: "come out at B".
Answer
The prover opens only the part of the envelope that answers that question. Someone who knows the secret always gets it right; a bluffer fails half the time, and each extra round halves the chance of a successful bluff.
In the proofs used today, the challenge does not come from a person: it comes from a scrambled calculation over the envelope itself, which nobody controls. That way the proof becomes a single message anyone can check later, without talking to the prover.
What proving costs, in milliseconds.
We built four practical proofs and measured them on an ordinary machine (Apple M2, 8 GB), with the open-source gnark library, in Go. The age proof takes 26 milliseconds to generate and 1.4 milliseconds to check, and takes up 164 bytes, less than this sentence.
The cost grows with what is being proved. Proving you are on a list of a million names, without saying which, takes 220 ms. Proving you know the text behind a SHA-256 fingerprint takes 1.6 seconds and needs a 51 MB key. Checking, in every case, takes a few milliseconds.
We also tried to cheat: a 16-year-old, someone else's ID, a proof reused with a different year, a balance below the amount. None of the four produced an accepted proof.
For use in practice.
What the proof does not solve.
The proof is worth what the issuer attested
The math guarantees the sentence follows from the signed data. If the issuing authority signed a wrong date, the proof proves the wrong date, perfectly.
The proved program can be wrong
What gets proved is that a program was followed. If the program says "greater than 17" where the rule says "18 or older", the proof stays correct and the rule is broken. The program needs its own audit.
Some systems need a ceremony
The most compact proof system needs an initial setup with a secret that must be destroyed. If it is not, whoever kept it can forge proofs. There are systems without that requirement, with larger proofs.
The proof hides the data, not the context
The verifier does not see your date of birth, but does see that someone proved their age, from which site, at what time. That trail needs care of its own.
Does this apply to your case?
Tell us in two lines what you need to decide or measure. The first conversation is to see whether measurement solves your case, and if it does not, we say so.
- Goldwasser, Micali and Rackoff, "The knowledge complexity of interactive proof systems" (1985), the origin of the idea. The cave: Quisquater, Guillou et al., "How to explain zero-knowledge protocols to your children" (CRYPTO 1989).
- ECA Digital: Brazilian Law 15.211/2025, in force since March 17, 2026, requiring reliable age verification and banning self-declaration.
- European Commission, age verification blueprint (July 2025); Google, open-source age proof (July 2025).
- Our own bench, September 2026: gnark v0.16.3 in Go, BN254 curve, Apple M2 with 8 GB. Full method and numbers on the bench page.