Credential-gated access for financial services: the holder presents once, from their own wallet; the service receives a verdict — never the documents, never the claims.
Every financial service repeats the same identity checks. Users submit the same documents to every provider.
Raw documents, passports, and biometric data sit in siloed provider databases — each a breach waiting to happen.
Compliance signals don't travel. A verified user at provider A remains unverified at provider B.
GDPR mandates data minimisation. Most compliance stacks are architecturally incapable of it.
A credential presented from the wallet can satisfy every service whose policy accepts that type. Each service decides fresh, at the moment of access, from the presentation itself.
OHNexus Protocol's own records hold outcomes and hashes, never claim values — no credential payload, no PII, no biometric data, by architecture. The verifier component OHNexus Protocol operates retains presentation sessions in memory for the lifetime of its process; that retention is upstream and is not claimed away here.
Credentials are SD-JWT VCs delivered over OpenID4VCI and presented over OpenID4VP — open standards, held in the user's wallet. No lock-in to any issuer or platform.
GDPR Art. 25 is the design source: data minimisation at the data-model layer, shaped by an independent legal design review of the privacy model (March 2026) — a review of the design, not a current audit. A design commitment, not a compliance certification.
A trusted issuer — your KYC provider, an accredited authority, or the platform itself — issues an SD-JWT verifiable credential to the user's own wallet over OpenID4VCI. Signed by the issuer, bound to the holder's key.
The user presents from their wallet over OpenID4VP, disclosing only the claims the service's policy names. The presentation is verified by a verifier the platform operates, and the issuer is checked against the platform's trusted-issuer registry.
The backend computes the verdict from the presentation and anchors the execution on Sepolia as hashes only — an execution id, the service code, a content hash. No identifier, no claim, nothing that names the holder. The service receives the verdict, never the credentials.
Cryptographic verification of SD-JWT credentials and presentations through a dedicated verifier service the platform operates. OHNexus Protocol's own stores keep no presentation payload — only a SHA-256 hash for audit correlation; the verifier's in-memory session retention is a separate, upstream matter. Issuer trust is checked against a control-proven registry.
Every service defines its own credential requirements — type, issuer, claim values, expiry. The eligibility engine evaluates all mandatory requirements in a single pass and writes a deterministic GRANTED or DENIED outcome. No caching. No stale state. Always a fresh evaluation at invocation time.
On AUTHORIZED, the protocol calls the publisher's provider API and, where the service declares it, issues a platform-signed credential to the user's wallet. The execution is anchored on Sepolia via the ServiceRequests contract as hashes — never a holder identifier. Provider endpoints receive no user credential data, no claim values, no PII.
Fintechs, asset managers, regulated data providers
Retail investors, institutional participants, regulated individuals
MiFID credential type exists in the platform registry today. What a gate requires is the publisher's own policy, written in plain language; the platform makes no regulatory claim on their behalf.Full Verify–Eligibility–Execution stack, with the business logic tested in isolation from any cloud dependency.
Credentials are held in the user's own wallet app and presented over OpenID4VP. No custodial wallet, and no browser wallet of ours — the holder brings their own.
ServiceRequests contract deployed on Ethereum Sepolia. Every AUTHORIZED invocation anchored with a cryptographic execution ID.
End-to-end: draft wizard → validate → publish → credential-gated invocation → auto-issued VC to user wallet.
Institutions write their policy in plain language in the Publisher Studio, and verify inside their own sites through the embed — their server receives the verdict, the browser leg carries no authority.
One deployed environment, on Ethereum Sepolia. Every shipped presentation path was walked there end to end with the Sphereon wallet. Not a production service.
The financial system runs on trust. But trust today means handing over your passport to every gatekeeper. We built OHNexus so that proof of trust becomes portable — held by the user, verified by math, never stored by anyone.
OHNexus Protocol runs today as a sandbox on dev.ohwnly.eu for financial service providers and institutional participants who want to see credential-gated access work end to end. An assistant explains and guides — it never decides; every verdict is computed by the backend from a presentation. Schedule a demo to walk it with us.
Privacy-preserving. Cryptographically verifiable. Built on open standards. OHNexus is the middleware between who you are and what you can access.