@zanii/age-assurance
v0.2.0
Published
Provable age-gate attestations without storing the ID - a real 2026 regulatory wave (UK Online Safety Act, EU, US state laws). Prove an age threshold was checked (over-18, over-13) by a named method/provider, committing only a salted subject reference and
Downloads
291
Readme
@zanii/age-assurance
Prove the age gate happened — without storing the ID. A real 2026 regulatory wave (UK Online Safety Act, EU, US state laws) requires age assurance for minors' services. The privacy trap: proving "we age-gated this user" usually means keeping their ID or DOB — the exact honeypot regulators also punish. This proves the gate happened while storing neither.
npm install @zanii/age-assurance @zanii/coreimport { buildAgeAssertion, verifyAgeAssertion } from '@zanii/age-assurance';
// stores a SALTED subject commitment + threshold + result + method — no DOB, no document:
const { payload, salt } = buildAgeAssertion({ subject: userId, threshold: 18, satisfied: true,
method: 'document', provider: 'yoti', ts: now });
await zanii.record({ target: payload.target, payload });
// verify: satisfied, meets the required threshold, and your injected provider verifier authenticates it
const r = await verifyAgeAssertion(payload, { requireThreshold: 18, verifyProvider, evidence });
r.ok; r.threshold;Python: from zanii.age_assurance import build_age_assertion, verify_age_assertion, ...
Injected provider verification
The actual age check is done by a provider (a verification service, a document/liveness
check, a reusable digital-ID credential). You pass a verifyProvider that authenticates its
evidence (the @zanii/attest discipline). Provider/method spoofing is caught; a failed
gate is recorded and verifies as not-ok too.
The limit, stated up front
This proves an assertion was made ("provider X, method Y, asserted over-18 for this subject at this time"). It does NOT assert the person truly meets the threshold — that's the provider's job, and no downstream proof is stronger than it. Storing nothing is the feature: an auditable gate without an ID honeypot.
