TL;DR: Privacy-preserving age tokens, passkey binding, and device-local reuse are becoming practical at scale, with Yoti saying it has completed 1 billion age and identity checks globally and now supports millions of token generations each month. The key issue is governance, not novelty: verifiers need age assurance without building cross-site tracking into the identity layer.
NHIMG editorial — based on content published by Yoti: privacy-preserving age tokens, passkey binding, and reusable age proofs
By the numbers:
- Over 21 million people globally have downloaded the Yoti Digital ID app, with many using it regularly to prove their age online.
Questions worth separating out
Q: How should organisations set age assurance rules for different services?
A: Start by defining the minimum acceptable proof for each service, then separate high-assurance checks from lower-confidence methods such as inference-based estimation.
Q: Why do device-bound age proofs improve privacy without solving governance by themselves?
A: They reduce repeated disclosure and help prevent cross-site tracking, but they do not tell the organisation when reuse becomes too permissive or whether the proof is suitable for a particular regulated flow.
Q: What breaks when age tokens are reused without clear acceptance criteria?
A: The programme loses consistency, because one service may accept a weak proof while another demands stronger verification.
Practitioner guidance
- Define age assurance acceptance tiers Set explicit levels for which proofs are acceptable for each regulated use case, including document-based checks, facial age estimation, and inference-based methods.
- Treat passkey binding as part of the assurance chain Document device custody expectations, key protection requirements, and conditions under which a passkey-bound token can be reused on shared or managed devices.
- Separate privacy claims from operational evidence Record how your age verification policy is enforced at the relying party, including audit evidence, retention rules, and exception handling for regulated access decisions.
What's in the full article
Yoti's full article covers the operational detail this post intentionally leaves for the source:
- Examples of the 10 different age-checking methods and where each is most appropriate in production.
- The mechanics of Yoti Key binding across browsers, private browsing modes, and device-local storage.
- Operational examples of how regulated adult platforms and retailers are accepting age proofs today.
- The article's description of how millions of monthly age token generations behave at scale across countries and use cases.
👉 Read Yoti's analysis of privacy-preserving age tokens and passkey binding →
Age tokens and passkey binding: what it means for IAM teams?
Explore further
Age assurance is becoming an identity governance issue, not just a privacy feature. Once a proof can be reused across multiple sites, the relying party has to decide what level of verification is sufficient, when device binding is acceptable, and how to avoid turning age checks into durable identifiers. That places the control problem squarely inside IAM policy design, not only product UX. Practitioners should treat age tokens as governed identity artefacts, not simple yes or no responses.
A few things that frame the scale:
- From our research: 50% of organisations are onboarding new vaults without proper security approval, introducing vulnerabilities and misconfigurations from the outset, according to the 2025 State of NHIs and Secrets in Cybersecurity.
- From our research: 91% of former employee tokens remain active after offboarding, leaving organisations vulnerable to potential security breaches, according to the 2025 State of NHIs and Secrets in Cybersecurity.
A question worth separating out:
Q: Who is accountable when age verification fails a regulatory review?
A: Accountability usually sits across product, compliance, legal and security because the failure is both operational and evidentiary. The organisation should assign ownership for threshold setting, logging, testing and retention so no single team can treat the control as complete on its own.
👉 Read our full editorial: Privacy-preserving age tokens are moving from theory to scale