Prove anything you can see on the web

Your Spotify top artist, your Duolingo streak, your Discord profile. If you can see it when logged in, you can prove it to someone else, revealing only the fields you choose and never your login.

Checking for the extension…Checking the verifier…Checking the credential service…

Proofs you can try now

Each proof opens the site in a window, you log in as usual, and only the listed fields are revealed.

Prover mode:   · Proofs marked "example" pin their own mode.

How it works

Three steps, no cooperation from the website needed.

You log in, as always

The extension opens the site in its own window. Your login goes straight to the site; we never see it.

A verifier witnesses the connection

Using the TLSNotary protocol, a server we run confirms the data really came from that site, while seeing only encrypted traffic.

You choose what to reveal

An approval screen shows the exact bytes before anything leaves your browser. The rest stays hidden. You receive a signed credential.

Get the extension

WebProof is a Chrome extension (also Edge, Brave and other Chromium browsers). It is not on the Chrome Web Store yet, so it installs as an unpacked extension:

  1. Download webproof-extension.zip and unzip it.
  2. Open chrome://extensions and switch on Developer mode (top right).
  3. Click Load unpacked and select the unzipped folder.
  4. Reload this page. The status line above turns green when the extension is detected.

Chrome will warn that the extension can read data on all sites. It needs that to see the requests of the verification window it opens; it does not observe your other tabs. See the FAQ.

Questions

What leaves my browser?

Only the fields you approve on the reveal screen, plus the fact that a verified connection to that site took place. Your login, cookies and everything else on the page stay on your device; the verifier sees encrypted traffic only.

Who is the verifier, and why trust it?

We run it. The cryptography guarantees it cannot forge or alter what the site sent, and it cannot read anything you did not reveal. Whoever accepts a credential trusts our signing key, published at the verification page. Anyone can check a credential there.

Why does the extension need "read all data on all websites"?

To capture the session headers of the window it opens for a proof, on whatever site the proof targets. It only observes windows it created for a verification.

What is Proxy versus MPC mode?

Proxy mode is fast: the verifier relays your encrypted connection. MPC mode has your browser hold the connection while the verifier participates cryptographically; it is slower but requires no trust in the verifier's network. Both produce the same credential.

A proof failed with "session expired"

Some sites time out their login after a while. Log in again in the window that opened and run the proof again.