About Lemma
Fraud is an economic
problem, not a tech one.
The industry already knows how to detect abuse. What it can't do is make a ban stick when the next account is free. lemma.id fixes the economics: users hold a private lemma.id, each site sees its own private ID, and a site can require a verified human behind an account when that's what actually matters. Nobody has to build a central identity database to get there.
For users the deal is simple: verify once, then show each site a proof that says "same returning person as last time" without saying who you are.
The problem
Detection is solved. Enforcement isn't.
Trust and safety teams have had good signal for years. Device fingerprints, velocity checks, behavioral models. Detection isn't the hard part anymore. The hard part is that a ban is only as strong as the cost of the next account, and right now that cost is close to zero. A fresh email, a new SIM, a residential proxy, and the person you banned yesterday is a brand new user today.
The one thing an attacker can't cheaply rotate is a real, verified identity. That's the lever. With lemma.id, a site starts with private continuity through a stable PPID, the same lemma.id coming back. When it requires a human proof, that PPID is backed by an actual verified person. A blocked user can't get a clean account by swapping infrastructure. We're not trying to make a new identity impossible, just expensive enough that the abuse stops paying for itself. For most abuse, that's all it takes.
The usual objection is that this requires surveillance, and it's a fair worry. Government digital ID, federated SSO, on-chain identity: they all create a new place where someone can watch who you are and where you go. Lemma is built so that doesn't happen. Sites only ever see site-private pseudonymous IDs, never one global identifier. The web has been stuck choosing between no real accountability and centralized identity surveillance. You don't have to pick either.
The thesis
Make digital ID work the way
physical ID works
A driver's license works because it's verified locally. When you show it at a bar, the bartender checks the hologram and the photo on the spot. The DMV doesn't get a notification. The license sits in your wallet, and you decide when to pull it out.
Lemma applies that model to the web. You create a lemma.id once. Each site asks for the proof level it needs, lemma.id continuity, a presence proof, or a human proof, gets its own private PPID, and checks proofs locally using Ed25519 signatures and cached revocation data. When a site requires a human proof, those proofs are rooted in a verified person, so the site can block an abuser and know that returning means passing verification again, not just grabbing a new email.
To be clear about what this doesn't do: issuance, revocation, recovery, and first-time setup for a site still need infrastructure. The control plane doesn't disappear. The privacy win is narrower and more practical than that. Routine access checks don't phone home to the identity verification provider, and no credential carries a stable identifier that follows you across sites.
Principles
What makes Lemma different
Local hot path
Credentials live in the user's lemma.id. Once setup and revocation sync are done, a site validates signatures on its own machines. There's no identity provider in the loop on every access decision.
Verify once, reuse everywhere
Today, lemma.id uses Didit for the underlying identity verification, and Lemma issues the reusable credentials on top: the local identity store, the SDK, the revocation infrastructure. A site that needs one-person-one-account gets it without ever storing an identity document, and users don't redo KYC for every site that asks.
Less to correlate
Because every site gets its own PPID, there's no single identifier tying your accounts together across the web. Each party stores less and sees less at runtime. See the full trust comparison →
Fits inside your flow
The way Stripe made payments something you embed rather than build, sites drop in the SDK and request proof inside their own signup or checkout. No redirect to an identity portal, no identity store to run afterward.
Founder
Why we're building this
Jed McKenna
Founder & CEO
Lemma started with an observation about the attacker's side of the ledger: scalping bots treat CAPTCHA as a line item. Commercial solving services charge well under a cent per challenge.1 So the puzzles mostly annoy real people while the professionals route around them with automation, cheap solving labor, and account farms. Whatever "proving you're human" should mean, it can't rest on puzzles.
The second observation was that most proposed fixes quietly create a new place to watch identity use across the web. Centralized digital ID does. Federated SSO with broad visibility does. On-chain identity broadcasts your interactions by design. None of that is a reasonable default for ordinary websites. A driver's license is the better model: issued by a trusted party, carried by you, checked where you use it.
Lemma is the thing I wished existed: verification that works for sites without turning them into identity stores, and for users without feeding a central identity database.
Where we're headed
Identity rails for the open web
The web needs identity infrastructure that AI-driven abuse can't cheaply farm, that doesn't route every login through a provider who can watch it, and that doesn't ask every website to become a regulated KYC operator. Nothing that exists today manages all three.
That's what we're building. One user-held lemma.id, a private PPID for every site, and three levels of proof, lemma.id continuity, presence, and human proof, wherever one account genuinely has to mean one person. The same primitive, working the same way, everywhere on the web.
The verification itself currently runs through Didit. Lemma's job is everything around it: the reusable credentials, the user-held lemma.id, the SDK, and revocation. A site adds the SDK and gets human-grade signal without ever holding an identity document. A user verifies once and carries it with them, and no site ever sees more than its own private proof.
Get involved
Lemma is early, and early feedback shapes the product. If any of this sounds like your problem, we'd like to hear from you.
Verify yourself
Create a lemma.id and use it on any site that supports it. If a site requires a human proof, you verify once and you're set.
Get verifiedAdd lemma.id to your site
A script tag and a backend check. Add lemma.id continuity now, and require a human proof later if abuse shows up.
View docsBecome an issuer
If you're an IDV provider, Lemma puts your verification in front of consumer sites your enterprise sales team will never call on.
For IDV issuersGeneral inquiries: [email protected]