Witness support
Whatever the problem is, a person reads these and
answers. There is no ticket queue to disappear into.
Getting started
What Witness does
Witness measures your camera's own sensor, and proves that the
video it publishes came from that camera. The person on the other end
checks that proof in their browser, and does not need to install
anything. Their page also shows them a small picture of your face, cut
by Witness from the very frames it checked and sealed so that nothing
on the way could change it.
What your meeting app then shows them is a separate thing, carried
by that app and not checked by Witness. The person checking compares
the picture on their page with the face on the call. See
the picture below.
Setting it up
Install the app, sign in, and follow the enrolment steps. Enrolment
measures your camera's own sensor, which is what later proofs are
compared against, so it takes a couple of minutes and needs decent
light. You only do it once per camera.
Starting a verified call
Select Witness Camera as your camera in Zoom, Meet,
Teams or any app that lets you choose a camera, and Witness starts
verifying on its own. Read the code from the Witness menu to the
person you are speaking with, or paste the address and code into the
meeting chat. They type the address themselves and enter the code. Do
not send them a link.
Can I use a driving licence instead of a passport?
Not today. Witness reads the chip inside a passport, which carries a
signature from the issuing government that your phone can check on its
own, without sending the document anywhere. Most driving licences have
no such chip. Digital licences are arriving, in the mobile driving
licence format some regions have started issuing and in the European
digital identity wallet, and those carry signatures of the same kind.
Support for them is on our list once they are common enough to rely
on. Until then, the passport is what we can verify without trusting a
middleman, and that is the point of using it.
Reading the verification page
The badge
The badge is about the camera. Green means a recent
check passed and the proof is current. Amber means the last check
passed but is getting old. Grey means no recent check has arrived and
nothing has failed. Red means a check did not pass.
The picture
Beside the badge is a small picture of the sender's face. Witness
cut it from the frames it checked against the enrolled camera, sealed
its fingerprint into the record the checks sign and the proofs cover,
and encrypted it so that only the person holding the code can open it.
The page opens it and checks it against that record itself. A picture
that does not match shows red, and the page says so in those words.
The video in your meeting app is not checked by Witness. Compare it
with this picture. If the face on the call is not the face in the
picture, the call is not what it claims to be, whatever the badge
says.
When something is not working
The badge is grey and nothing is happening
The usual cause is that the meeting is not using Witness Camera, so
nothing is being sent through the verified path and there is nothing
to vouch for. Check the camera selected in your meeting software.
The other person says the code does not work
Codes stop working when you end the session, and they expire on
their own. Start a call and read them the current code, letter by
letter, from the menu.
Checks paused, no agreed randomness
Witness uses a public randomness beacon that several organisations
publish together. If they are unreachable or disagree, checks pause
until that resolves. Your camera has not failed anything, and the page
says so in those words.
I have lost my passkeys
If Google sign-in is connected to your account, sign in with it on
the account page and add a new passkey. If not,
choose "Lost your passkeys?" under the sign-in form and enter your
address. A link goes to the mailbox that made the account; open it on
the device the new passkey should live on, approve the prompt, and you
are signed in with the new passkey added. Your identity, your devices
and your receipts are untouched: an account holds none of them. Remove
any old passkey you no longer hold from the account page afterwards.
Enrolment will not complete
Enrolment needs steady light and a still camera. If it keeps
refusing, email us with what the app said. A refusal is deliberate: an
enrolment that is not good enough would produce checks that fail later
for no reason.
What Witness does not claim
Witness proves that frames came from a particular enrolled camera.
It does not prove that the person in front of that camera is who they
say they are unless they have chosen to link a verified identity, and
it cannot tell you what happens to those frames after they leave the
verified path. Where we do not know something, the page says so rather
than filling the gap. Three things in particular it cannot see: a screen
or a mask held in front of a registered camera, a camera physically
swapped for another, and a machine whose system protections were
switched off. From macOS 27 the page says whether the sender's Mac
attested that its protections were on; before that, it cannot tell. If
any of our software ever claims more than that, tell us, and treat it as
a bug.
Privacy and your data
You can export everything we hold about your account, and delete
your account, from your account page. Your camera's measurements stay
on your machine: what reaches us is proof, and a small sealed picture of
your face that only the person you are calling can open.
See the privacy policy and
terms of use.