Web3 identity has crossed the standards threshold
Web3 identity is no longer waiting for basic standards. W3C made Decentralized Identifiers 1.0 a Recommendation on July 19, 2022. Verifiable Credentials 2.0 became a W3C Recommendation on May 15, 2025. OpenID for Verifiable Presentations 1.0 reached Final Specification on July 10, 2025, and OpenID4VCI 1.0 defines OAuth-based credential issuance flows for wallets and issuers.
Mainstream identity guidance has moved in the same direction. NIST published its digital identity guidelines on August 1, 2025, and the Revision 4 project material explicitly highlights two changes that matter for Web3 builders: controls for forged media and deepfakes, and the addition of subscriber-controlled wallets in the federation model.
The practical implication is straightforward. Web3 identity is now a deployable stack, not a research slogan. That is increasingly clear in digital identity verification use cases. The hard part has shifted from cryptographic possibility to governance, issuer trust, wallet UX, and economic access rules. That shift matters because once identity controls who can claim rewards, vote, or receive an airdrop, identity stops being a product layer and becomes part of the token economy.
Most “decentralized identity” systems decentralize different layers
Most systems in this category decentralize only some layers, not all of them. Ethereum’s own identity overview describes the chain primarily as a verifiable registry for identifiers and issuer keys, while attestations and credentials can remain offchain in user wallets. W3C’s data integrity work takes the same direction. Credentials are meant to be cryptographically verifiable without forcing personal data onto a public ledger.
That creates four distinct control layers. Identifier control decides who names entities and where keys are resolved. Issuer control decides who is trusted to make claims. Wallet control decides who stores credentials and how recovery works. Verifier policy control decides which proofs count for access, rewards, or governance. Web3 usually improves the first and third layers. It only sometimes decentralizes the second. It almost never decentralizes the fourth.
Sign-In with Ethereum is the cleanest example of the limit. ERC-4361 standardizes offchain authentication for Ethereum accounts to establish sessions with web services. That gives users portable login and reduces dependence on large identity providers. It does not prove personhood, citizenship, age, uniqueness, or legal eligibility. SIWE solves account control. It does not solve scarce human allocation.
Credential wallets solve a different problem. The EU Digital Identity framework keeps issuance with member states, but pushes storage, presentation, and user-side disclosure into wallets. The European Commission says member states must make wallets available by the end of 2026, and the architecture is defined through a common reference framework and an open-source reference implementation. That is not “Web3” in the cultural sense, but it is converging with the same wallet-plus-credential operating model.
Attestation layers sit somewhere in between. Ethereum Attestation Service positions itself as a base layer for attestations across identity, trust, voting, and reputation use cases. That is powerful composability. It does not answer the deeper question of who gets to issue trusted attestations in the first place. In identity markets, the attester is usually the real power center.
Identity becomes allocation policy the moment tokens or governance are attached
Identity is economically neutral only until it starts gating scarce benefits. Human Passport is explicit about that. Its core product lets users assemble “Passport Stamps” from KYC, biometrics, web3 activity, web-of-trust signals, and web2 activity, and those signals feed builder-side access decisions. Its Data Services product is even more direct: it is marketed for airdrops, token distributions, community campaigns, and Sybil investigations, and it assigns a Unique Humanity Score from 0 to 100 using multi-chain analysis.
That means identity scoring is not just anti-bot infrastructure. It is distribution infrastructure. A score threshold decides who gets included. Accepted proof types decide who bears friction. A model that rewards prior onchain activity privileges incumbents. A model that leans on KYC or biometrics privileges users willing and able to submit stronger evidence. A model that relies on web2 exhaust privileges users with richer histories. The fairness question is not whether a system is “Sybil resistant.” The fairness question is whose lives are legible to that system.
World’s developer documentation makes the same economic connection from the other direction. It frames proof of human as appropriate for one-person-one-action flows and specifically cites rewards, referrals, governance, and account creation as target use cases. Once identity is used there, the verifier’s eligibility logic becomes a hidden cap table. That is why identity design belongs inside tokenomics analysis, not outside it.
World ID is the clearest test of tokenized identity’s upside and concentration risk
World ID is the most important live case because it combines reusable proof of personhood with an active token. World says World ID verification happens at an Orb, that the resulting proof is stored on the user’s phone, and that apps receive proofs rather than raw personal data. The same documentation says proofs are generated on-device and are unlinkable across apps.
As of April 28, 2025, World’s allocation structure reports the following:
| Category | Share of 10B initial supply | Why it matters for control |
|---|---|---|
| World Community | 75% | Large headline allocation, but World Foundation governs these tokens and decides how much goes to users, network operations, and the ecosystem fund. |
| Team | 11.1% | Meaningful early builder ownership. |
| TFH Investors | 13.6% | Capital providers retain a substantial stake in long-run governance and value capture. |
| TFH Reserve | 0.3% | Small, but still discretionary treasury capacity. |
The favorable reading deserves to be stated clearly. World’s whitepaper says user-claimed tokens are not locked, while team and investor tokens were subject to a 12-month full lockup and then mostly 48-month linear unlocks, with nearly all of those unlocks concluding by the end of July 2028. It also says the Foundation’s stated goal is to allocate at least 60% of total supply to users over time. Relative to many crypto launches, that is a serious attempt to tie ownership to broad participation rather than a narrow initial insider set.
The harder reading is that ownership dispersion at the endpoint does not remove control concentration upstream. World Foundation governs the 75% community bucket, decides the release path into circulation, and manages permissions for adding Orbs to the network. The whitepaper also says the active Orb registry is endorsed by the Foundation and that individual Orb manufacturers or even specific Orbs can be removed from the whitelist, with fraudulent Orb-linked World IDs potentially revoked. That is a real security mechanism. It is also a real control surface.
This is the core builder-incentive versus concentration-risk trade-off. Strong proof of personhood requires trusted enrollment hardware, audit processes, revocation paths, and treasury funding for global rollout. Those functions do not emerge spontaneously. But if one foundation can shape hardware admission, operator standards, token release, and the pace of user distribution before governance has genuinely diffused, then the identity layer can become more centralized than the token allocation headline suggests.
Privacy progress is real, but recovery and long-term reputation remain constrained
The strongest technical progress in this sector is privacy-preserving disclosure. W3C’s Data Integrity 1.0 specification explicitly defines selective disclosure, and the BBS cryptosuite says it supports selective disclosure and unlinkable proofs. World makes similar claims at the application layer, saying World ID uses zero-knowledge proofs and keeps underlying user data off the relying party path. The EU wallet framework likewise centers user control and data minimization.
The weaker part is continuity. World’s whitepaper is unusually candid here. It says actions associated with a particular World ID cannot be recovered today, that humanness validation should therefore be implemented with time bounds, and that persistent reputation use cases remain limited. That is not just a product footnote. It defines which economic systems can safely sit on top.
Short-horizon use cases work better than long-horizon ones under those constraints. Airdrop eligibility, single-vote governance, referral abuse control, and one-person-one-claim campaigns fit the current tooling well. Under-collateralized credit, durable contributor reputation, and identity-linked social capital are harder because privacy-preserving recovery and persistent reputation are still technically and politically unresolved.
What token designers should do before they add identity to a token economy
Separate wallet authentication from personhood. If the real need is portable login, SIWE may be enough. If the real need is trusted claims, verifiable credentials and presentation standards are the right layer. If the real need is one-human-one-action, then proof-of-personhood becomes relevant. Treating these as the same problem produces bad architecture and worse governance.
Publish eligibility logic as clearly as emissions logic. A DAO that discloses unlock schedules but hides identity thresholds is only disclosing half its distribution policy. If a Unique Humanity Score, KYC path, passport requirement, or Orb verification decides access, that rule belongs in the public spec just as much as vesting or inflation does.
Measure concentration at the issuer and verifier layers, not just the token ledger. A broad user distribution can still mask centralized control if one entity controls hardware whitelists, verifier defaults, or treasury release discretion. In identity systems, those levers often matter more than the raw initial holder count.
Design for low-data proofs first. The winning architectures are moving toward selective disclosure, local wallet storage, and proof-based presentation rather than onchain PII dumps. That is not just better privacy. It reduces vendor lock-in and lowers the blast radius of future policy changes.
Prefer time-bounded entitlements unless recovery is solved. If persistent reputation cannot yet be recovered or safely transferred, then long-duration rights should not depend on it. Temporary voting windows, claim periods, epoch-based participation, and recurring re-validation are usually safer than permanent identity-linked entitlements.
For teams doing token economy design, identity policy is now part of ownership design. The decisive question is no longer “should we use decentralized identity?” The decisive question is who gets legible access to economic participation, who sets that gate, and how reversible that power is once the system scales. At FinDaS Tokenomics, that is where tokenomics consulting stops being an emissions exercise and becomes a fairness analysis of issuers, verifiers, treasury discretion, and real user inclusion.
