PROVE IT

SECURITY & PRIVACY

PROVE IT verifies achievements. It doesn't need access to your money, passwords, or private information to display them.

VERIFY WITHOUT OVERSHARING.

Your badge is public. The numbers, accounts and wallet data behind it stay private.

CRYPTO

WALLET VERIFICATION

PROVE IT uses a cryptographic signature to confirm that you control the wallet you connect. Your wallet signs a short text message; nothing is sent to the blockchain.

  • Signature only
  • No transaction
  • No gas
  • No spending approval
  • No access to funds
  • No seed phrase
  • No private key

Signing the PROVE IT verification message does not give PROVE IT permission to move, spend, approve, or transfer assets.

PROVE IT will never ask for:

  • Seed phrase
  • Private key
  • Wallet password

If you ever see a request for any of those, do not continue.

The message you sign

PROVE IT Wallet Verification

Sign this message to prove ownership of this wallet for PROVE IT.
This signature does not authorize transactions, transfers, approvals,
or access to your funds. It is free and sends nothing on-chain.

Wallet: 0x…
Account: <your PROVE IT account id>
Nonce: <one-time value>
Issued at: <timestamp>

The nonce is generated per request, the message is bound to your wallet address and your PROVE IT account, and it expires 10 minutes after it is issued. Signatures themselves are not stored.

What we read after ownership is proven

PROVE IT reads public blockchain information only when necessary to verify eligible achievements:

  • Wallet age (first on-chain activity)
  • Transaction count threshold
  • Qualifying NFT ownership (Bored Ape Yacht Club balance)
  • Eligible ETH history (current balance and first inbound transfer date)

All of this is already public on Ethereum. It is read server-side and kept out of your public Passport: the Passport shows the achievement, not your financial information.

SOCIAL

SOCIAL VERIFICATION

PROVE IT uses the official authorization systems provided by the supported platforms — YouTube, Instagram and Twitch. PROVE IT never asks for your social account passwords; you sign in on the platform's own page and approve the request there.

The permissions below are exactly the scopes the current implementation requests.

YOUTUBE

Used to verify: subscriber milestones.

WHAT WE USE

https://www.googleapis.com/auth/youtube.readonly

This is Google's read-only YouTube scope: it allows reading your YouTube account data, including your channel and its subscriber count. It does not allow uploading videos, posting, or modifying your channel. We read your channel once per verification.

INSTAGRAM

Used to verify: follower milestones.

WHAT WE USE

instagram_business_basic

Instagram Login's basic permission for professional accounts. It allows reading your profile information and your media, including your follower count. It does not include publishing, messaging, comment moderation or insights permissions. We read your profile once per verification.

TWITCH

Used to verify: follower milestones.

WHAT WE USE

moderator:read:followers

A read-only Twitch scope that allows reading the follower list and total follower count of a channel you own or moderate. It does not allow streaming changes, chat actions, channel edits or any write operation. We read the follower total once per verification.

EXPOSURE

WHAT YOUR PASSPORT SHOWS

PROVE IT is designed to prove achievements without requiring you to reveal all the underlying information. Your Passport is private until you publish it, and publishing is opt-in.

PUBLIC

  • Badge earned
  • Achievement name
  • Verification status and date
  • Public milestone (e.g. 100K+), where applicable
  • Your display name and handle

PRIVATE

  • OAuth tokens (never stored — used once, server-side)
  • Exact follower / subscriber counts
  • Wallet balance
  • Full wallet address
  • Wallet transaction history
  • Private verification evidence
  • API credentials

Private verification data is stored in a separate, restricted table that public views never read. Platform tokens are exchanged and used inside server handlers only; the browser never receives them and they are not persisted.

HONESTY

WHAT WE DON'T CLAIM

No product is risk-free, and we won't pretend otherwise. PROVE IT depends on third-party platforms and public blockchain data, so we describe exactly what we request and store instead of making absolute security promises. If something here doesn't match what you see in the product, stop and tell us.