A privacy-preserving, minimal-disclosure age check that reuses banks' existing KYC, with the user as the transport layer.
- A bank authenticates an existing customer and signs a short-lived age-threshold claim - not their name, date of birth, account number, or other identity details.
- The merchant binds that claim to its own nonce and a fresh WebAuthn credential, then atomically consumes the claim in a short-lived, single-use replay ledger. The reference verifier uses Redis.