Verifiable Credentials: Who Should You Trust?
Ankur Banerjee CTO and co-founder, cheqd (at recording)
A valid signature does not establish that a credential's claims are true. In this August 2023 interview, cheqd co-founder Ankur Banerjee explains why verifiers need trusted issuers, why personal details belong offchain, and how social reputation can travel between communities. He describes Creds.xyz wallet backups and asynchronous sharing, then explores identity beyond passports and KYC. Product descriptions and plans reflect the recording period.

- At 03:05, Banerjee explains the privacy cost of public NFT reputation. Once a wallet address is linked to a person, its public holdings become linkable too. He describes keeping personal credential details in offchain wallets and using public verification material. The W3C DID privacy guidance also warns against personal data in public DID documents.
- At 08:13, Banerjee distinguishes a genuine issuer’s credential from a self-written claim. Trusted issuer lists address who is credible for a particular claim. The W3C Verifiable Credentials trust model makes verifier trust a separate decision; a verifiable signature does not establish truth.
- At 11:37, he describes a browser wallet with end-to-end encrypted backups decrypted on the user’s device. He also describes time-limited links and snapshots for people in different time zones. These are the 2023 product descriptions; encryption and asynchronous sharing do not by themselves prove selective disclosure or a particular zero-knowledge protocol.
- At 16:16, he broadens identity beyond government documents. DAO contribution, loyalty membership and shopping preferences are also identity-related data. His token-threshold example relies on a DAO-issued claim and is distinct from legal identity or KYC.
- At 21:15, Banerjee argues that downloading an account archive is different from moving verified reputation to another service. His example involves proving control of a former social handle. It is a proposed use case, not a guarantee that Twitter, Threads or Mastodon support such imports.
Introduction, cheqd and portable reputation
Watch this part · 0:00Kevin Wavect, the Web3 software company that understands what you want. Hi everyone, welcome at Wavect, today with a special guest, Ankur from cheqd. Today we will talk about a super exciting topic: decentralized identity and how to truly own your data. Thanks, mate, for being here. It's really a pleasure talking with you. Starting out, I want to give you the opportunity to introduce yourself, to let us know what you're currently working on and whatever you feel is worthwhile to share here.
Ankur Sounds good, and thanks for having me here, Kevin. Very excited to be on your podcast. My name is Ankur Banerjee. I'm the CTO and co-founder at cheqd, [pronunciation aside unclear], and we are a decentralized digital identity network built on Cosmos SDK. What we are trying to do is make your data more private, more secure, more portable. We can go into a bit more detail on how all of that works. What I'm currently working on, and what is extremely exciting, is an associated project called Creds.xyz. Creds.xyz, which I personally lead, builds on top of the cheqd network. It's all about decentralized social reputation: how can people within Web3 communities carry their social reputation as members within a community or members within a DAO to other communities? That's pretty exciting because we feel it's one of those use cases people more immediately recognize, although the broader application of our technology can be quite wide. In terms of my passions, I really look forward to building a new web or new internet where people have far more control over their own personal data. I think it's an absolute shame that this was not baked into the models of the internet when it first started, or the World Wide Web over the past 20, 30 years. I'd really love to see some of these very large tech companies disrupted, who are the gatekeepers of our data quite often.
What belongs onchain and what stays private?
Watch this part · 2:35Kevin Love it, great mission. You just mentioned Creds, and I had a quick look at it as well. I would be really curious: you just said you're tying in, from my understanding, onchain reputation, like when you join the DAO and contribute to some kind of project. Do you also try to solve the gap between offchain data and onchain reputation, or how are you thinking about that?
Ankur That's an excellent question. We do use a blend of onchain and offchain reputation or storage. Traditionally, if you think of decentralized identity, people try to solve it by putting some information into an NFT or a proof of attendance, or POAP if you've heard that term, and writing that onto chain. It's very useful for a lot of things that are status symbols. It's a bit like parking a Lamborghini or Ferrari outside your house and making all your neighbors feel jealous. It's great for that. But the challenge with NFTs or other onchain storage is that it is public for anybody to view and see. You could have it in a wallet address that is not tied to you, but if at some point somebody finds out that is the wallet address belonging to Kevin, they'd be able to figure out what NFTs you hold there. So we use a blend of onchain and offchain reputation. It's built on an international standard built by the World Wide Web Consortium, or W3C. You might hear that term a lot. It has involvement from not only Web3 companies but traditional Web2 companies like Microsoft, Mozilla and Google as well. The basic idea is that onchain you store public keys and public signatures that allow you to check that some data is tamper-proof. You store the actual details about your social reputation, healthcare, education record, employment history, any number of use cases, in offchain wallets. These wallets can be like browser extension crypto wallets, on mobile, even stored on physical cards. I've seen that and worked on projects that did that. They could be printed out as QR codes on paper for backup, to have recovery seeds. The general idea is that if you had them purely stored in an offchain wallet or identity wallet, when you show this to someone to say, "My name is Kevin. I live in Germany. I'm the host of this podcast. I've been doing it for the past five years," you have that in a tamper-proof digital format within your identity wallet. When you show it to someone, they're able to check the stamp or signature that exists publicly onchain to verify that what you've shown them has not been tampered with. The example I use is a paper bank statement sent by your bank with a rubber stamp at the bottom. Storing onchain is like the rubber stamp: what does the stamp look like for this bank? But the paper, which contains your bank statement, transactions, address and name, is physically just with you. You get to choose whom you share it with. That doesn't prevent you from publishing some of these tamper-proof digital credentials publicly, the same way you might make your Twitter or Facebook profile, or certain things within those profiles, public and other things private. You still have that option. It gives a lot more flexibility and control over whom you want to share certain kinds of information with.
Does a valid signature make a credential trustworthy?
Watch this part · 7:15Kevin It sounds pretty interesting. Some context: my first touchpoint with crypto was a decentralized identity startup many years ago. [Ankur: Oh, wow.] What I remember as one of the biggest issues in creating a decentralized identity is issuance. How do you certify not just that the data has not been tampered with, but that the original data you issued onchain is actually true? What's your approach? Is it a similar approach to Polygon ID, if I'm not mistaken, where you have issuers who can input whatever data they want and it's on their reputation to certify whether that information is correct?
Ankur That's an excellent question: how do you understand whether a digital credential somebody holds is trustworthy? The analogy I use is a digital credential saying you're an employee of a company, issued directly by your employer. That is obviously more trustworthy from a human perspective than you writing it yourself on a sheet of paper with crayon, saying, "I'm the CTO of Twitter, now known as X." [Brief aside unclear.] When people see that, they will think, "I don't know how much I want to trust that piece of paper." But an actual employee badge or something that came from somebody reputable, they'd consider much more trustworthy. I'm glad you raised this question. We think this has been a massively missing step within a lot of decentralized identity over the past six or seven years that I've been working in this space, and in which it has existed. What we've designed within the cheqd network, where you publish these onchain elements, is the ability to publish trusted issuer lists. For example, if you wanted a credential issued by DAOs on Ethereum, people might create a trusted issuer list of trustworthy DAOs within the Ethereum ecosystem, their public keys and public signatures. Similarly, you might want to check the structure of the data inside. A passport is pretty standardized across the world: the different fields and the order they come in. Regardless of the language in which it's issued, when you travel to, I don't know, Tuvalu, they're still able to check what's inside your passport. We also allow people to publish associated elements in a tamper-proof fashion that solve some of the trust and reputation problems you were describing in decentralized identity.
How do encrypted wallets and sharing links work?
Watch this part · 10:41Kevin Okay. You mentioned before that you're able to share data publicly and privately. I'm pretty sure you're expecting this, with the recent hype around validity rollups: you probably use ZK, right? [Ankur: Yes.] Okay, cool. How is that interwoven with the public data? You host it offchain in your wallet, your app, your application, right? Then the user shares these claims? What's the high-level user flow? How does it work to share information?
Ankur Absolutely. There's two elements of zero knowledge. One part is how we design the identity wallet for Creds.xyz. It's purely within a browser. You don't need to download an application or a browser extension. We designed it very similarly to password managers. If you've used 1Password or Bitwarden, they synchronize your passwords across the three, four, five different devices you have. You enter a passphrase to unlock that wallet, but it's only ever decrypted on your own device. After a digital credential has been given to you, when we back it up, we do that in an end-to-end encrypted fashion, very similar to WhatsApp or Signal, or password managers like 1Password and Bitwarden. It allows you to log on and access this identity wallet on any device. However, when the encrypted backup is downloaded, you're only able to read the contents and what these digital credentials contain about your social reputation or other facts about yourself if you have the passwords. For public sharing, let's say you wanted a time-limited link: accessible for 24 hours, only clickable five times, or public forever in a collection on the website. When you're logged into the Creds.xyz wallet or similar SSI, self-sovereign identity or decentralized identity wallets, you essentially create a snapshot. It's the same as generating a QR code for your vaccine certificate, which many people had to do in the past two years, and you publish that. You can share the link with anybody who wants to view and verify those details. But they'll be informed that it was generated on, say, the first of August. If they access it three months down the line in October or November, they might want you to generate a fresh link and share it again, to still prove you're controlling and holding that wallet. It's something we did for a UX reason. A lot of decentralized identity wallets assume you're sharing digital credentials live and in real time. While that's true in some use cases, we don't think it's necessarily true in all. Imagine you wanted to prove your membership to a DAO to somebody on Telegram, but they're not in the same time zone. They might want to look at it eight hours later. How do you handle that? In this example, we take that snapshot, host it on their behalf and follow the rules they want to apply to it.
Why does identity extend beyond passports and KYC?
Watch this part · 15:18Kevin Okay. One question that comes to mind is a challenge identity solutions often have: why, from a user's perspective, would I use this? Identity, in the end, is verified by the government, right? [Ankur: Yeah.] Or public institutions, not companies. How do you go about that? What's the pathway for cheqd? Do you go to governments and try to integrate it there? Is it more business use cases, like a verified employee? Where is it going, what's the plan?
Ankur We have a very broad approach to where it could be applied. We do talk to some very large government agencies, or traditional digital identity, as I call it. That might be when you're asked to do know your customer, or KYC, with a bank or crypto exchange. Other examples are driver's licenses and passports. That's how we typically understand the word identity. I think it's broader than that. In the Creds.xyz social reputation examples, maybe you want to prove, when voting in a DAO, that you hold more than one million tokens without revealing the wallet address or exact figure. You just want to prove, "I have more than a million." It's a challenge right now: most DAOs give voting rights based on how much you have staked, and that just says how much money you have. It doesn't say you might be more important to the DAO for other reasons: you're a good contributor, a good governance contributor, or you make insightful comments. For that kind of credential, what we've been building on the Creds.xyz platform is a credential issued by the admins and moderators of that DAO. It might be tied to a pseudonymous handle like a Telegram or Discord handle. It doesn't have to be, but it could be, or a wallet address. It states the proof issued by the DAO, which knows what the address is, and says, "Yes, Kevin holds more than one million CHEQ tokens." What's interesting is that this isn't legal identity or legal know your customer. It is relatively pseudonymous. When you think along those lines, identity applies to a broad range of use cases which aren't government-issued. My Starbucks loyalty membership card, even though it doesn't have my name on it, personally belongs to me. It doesn't go through the same level of governance and assurance checks as getting a passport. There's still something that is my personal data. My preferences when buying clothing on ecommerce stores are also part of my identity and personal data related to me. In that broader context, I think decentralized identity has been quite focused on government-issued credentials becoming digital. My challenge is: how often do you need to show your education degree? If it were issued as a digital credential, I'd only have to do it once in my life for the first job. Ever since, that hasn't been a major factor. With know your customer, most people get their first bank account at 16 or 18, and they never have to do KYC until buying a house perhaps 20 years later. It doesn't happen that often. What happens way more often is interacting with social media, messenger applications, online forums and ecommerce. In all those places you're trying to share some kind of personality profile or data that customizes the experience for you. That is the much broader vision for digital identity.
Can downloaded data move your identity to another platform?
Watch this part · 20:28Kevin That's an interesting take. A personal thought: could this depend a little more on the use case itself? When I think of the big FAANG companies, Meta, Alphabet and so on, they would have the resources to use your data in a fully GDPR-compliant manner, speaking of Europe right now. But they don't, or just do the necessary evil to still pursue their business case.
Ankur They'll only allow you to download a copy. Under GDPR rights you can download your entire Facebook history, but you get a bunch of spreadsheets, computer-readable files and images you've uploaded. It's not very usable. You can't easily say, "I'm done with Facebook, I want to move to a new competitor platform, Mastodon." You're right: the FAANG and large tech companies generally enable the bare minimum they need to comply with the law. They don't make your data portable, at least not in an easy way to move to something else. Take a social media example. Let's say I was fed up with Twitter, like a lot of people are. I'm not, I do enjoy it, but let's say I wanted to shift to Threads. I might not have the same username or handle because somebody else has taken it. Just having the same handle doesn't mean it's the same person. Even if I downloaded all my Twitter data, you can't easily take it across in a portable fashion. With decentralized identity you could say, "I've set up a new account on Threads or Mastodon. I can validate that I used to be the same person or account, at least that I used to control this Twitter handle, and this is a verified import of my ten-year Twitter history," and prove those facts to someone. The European Union has been one of the more forward-looking regulatory frameworks here. There's something called the Digital Markets Act, which they recently passed, aimed at increasing competition and this kind of possibility. Even they realize GDPR doesn't actually give people a lot of rights. It maybe helps them delete their data with a company, that's one thing it gets right. Everything else isn't really informed consent. You see a cookie banner, everybody clicks yes, and you've given them permission to do whatever they want with your data. It doesn't help you move to a new service easily. I'm very excited about some of the regulatory changes happening. It would be exciting with the work we're doing with governments, to have a digital copy of government-approved or government-issued credentials, or government-regulated industries, like banking and healthcare. These are regulated for good reasons. A personal challenge I faced: when I see a new doctor, they don't have access to my medical files. At best I get a DVD. What am I supposed to do with that? I'm excited about those government-led use cases because they have a high degree of confidence, trustworthiness and reputation. I'm also curious about what could happen in the private sector if our data became more free-flowing.
A question for the next guest
Watch this part · 25:09Kevin Love that. I think that's a great ending for that part. If you don't mind, I'm trying to introduce a new tradition: you asking an arbitrary question to whatever guest comes next. It can be anything. It's probably a good idea not to have it too technical or too niche, because not every guest is technical. I leave that up to you.
Ankur My question for the next guest would be: what is the most interesting thing you've learned in crypto or Web3 in the past year? Something that surprised you and that you didn't originally anticipate or know about. I find that fascinating when I have that kind of discussion at Web3 or decentralized identity conferences. That would be my question for the next guest.
Where to learn more and closing
Watch this part · 26:15Kevin Love it. Thanks, Ankur. It was a pleasure talking with you. If you have any links for me to share in the video description, I'm happy to do so. Otherwise, thanks for taking the time out of your probably very busy day. Thanks everyone for watching.
Ankur The two links, which I'll send across to you as well: if you want to check us out, go to cheqd.io. That's our protocol-level network with 40-plus partners who are decentralized identity vendors, some of the largest names in the game. They work and build on our network. Check that out if you're more technically inclined. If you're less technically inclined or more interested in our social reputation, go to Creds.xyz and check out how we're tackling taking your social reputation anywhere, in a private, secure and portable fashion.
Kevin I love it. Thanks everyone. Thanks, Ankur, again. See you next time.
Ankur Thanks, Kevin.
Kevin Wavect, the Web3 software company that understands what you want.
Questions this episode answers
Want this kind of thinking applied to your product?
We build MVPs and act as fractional CTOs for founders who'd rather ship than talk.