← Back to all articles
Challenges

MintID Is Running in Production. Here Is Exactly What That Means — and What It Doesn't.

By Marc Molas·September 21, 2026·6 min read

In July I told you I had been building the thing I kept describing in the agent-identity series, and I showed you what it looked like. Today I can say something I could not say then: MintID is running in production.

I want to be precise about that sentence, because in this industry «live» is the most abused word after «decentralized». So here is the exact claim, and then the exact boundary of it.

What is live today

MintID runs in production on a private substrate operated by its first implementer, the CONECTIA group — the network's first accepted issuer, its first registered verifier, and the first product built on it. The code is open source under Apache-2.0 at mintid.net. Full disclosure, once and up front: I founded MintID and I am the beneficial owner of the group that builds and operates it. I am also founder-director of the Foundation that will steward the public network, and recused from every Foundation decision that concerns the group. That is on the site's About page in the same words; I'd rather you read it here too.

Four things sit behind the word «production».

  • A live network you can rebuild from zero. On 2 August we brought up the first end-to-end network: a chain node plus the verifier service, deployed on our own infrastructure, from a bring-up package. Tear it down, rebuild it, and you get the same network in minutes. Defects found in protocol code during that bring-up: zero. Everything that broke was deployment tooling, and it was fixed on the spot.
  • The full verification pipeline, end to end. Registration, proof-backed reads, challenges, decision records and the MCP surface for agents are all exercised on that network. The verifier SDKs — TypeScript, PHP, Python — are the ones I walked through in July: nine acceptance conditions always in full, a ten-second presentation lifetime that is a constant in the code, no policy surface an integrator can loosen.
  • The Protocol Whitepaper v1.0, dated 16 September 2026, with the specification corpus re-frozen after the economic-viability audit we published in July — a related-party review, and we said so, with a qualified opinion and five critical findings, all resolved.
  • A canonicalization standard we declared in public. How MintID hashes what it signs — RFC 8785 canonical JSON, then SHA-256, with typed digest references — is published as bIP-0003, aligned with an individual-submission Internet-Draft on payload binding. Declaring how you hash is dull. It is also the thing auditors ask for first.

What is not live, in the same font size

  • There is no public mainnet. The distributed network — sixty genesis validators, the launch gate measured in price-independent units — comes later, and not before two independent chain and protocol audits, a specialist cryptography audit, an infrastructure penetration test, an independent token and economic review, a public adversarial testnet, a funded bug bounty and an incident-response exercise. That list is a requirement, not an aspiration.
  • There is no public testnet. The network we run is an internal one: no third-party validator accounts, no join kit, no published endpoints. Publishing them is a decision we have not taken.
  • Zero-knowledge proofs are not yet being verified. The proof engine ships with the cryptographic-core milestone. Until then the pipeline fails closed by design: every presentation is refused with a proper reason code. A verifier that says «no» to everything is not impressive, but it is honest, and it is what you want from an identity layer before its cryptography is audited.
  • There is no token, no price and nothing for sale. The Foundation is dormant — no treasury, no contracts, no seats — until the public-offer route is chosen. Any allocation, fee or price figure attributed to MintID anywhere else is not ours.

If you only remember one distinction, remember this one: «in production on a private substrate» is a statement about software that works; «mainnet» is a statement about a network that nobody controls. We have the first. The second is what the audit list above is for.

The first product is already using it

ZadQ, an accountability layer for x402 seller endpoints, is the first product built on MintID and the group's own product line. It runs as a pilot on a private installation of the MintID software — not on the network — and I'll say the uncomfortable part myself: nothing measured in ZadQ counts toward the network's launch criteria. It counts as proof that the software carries a real product with real operators behind real endpoints. I've written up what ZadQ is and what it verifies separately.

Why a private substrate first, and not a testnet with a join button

I'd concede the objection before you raise it: a private substrate operated by the builder is the least decentralized thing a chain can be. Correct. It is also the only configuration in which you can re-freeze a spec five times, replay a bring-up from zero and find that the protocol code has zero defects before strangers are running validators on it. A public testnet with a join kit is a commitment to backwards compatibility you cannot yet keep. We chose to keep the promise small and true.

The order we're following is the one written into the roadmap: specs frozen, chain foundation, issuers and bonds and status, verifier registry, anonymous credentials — the phase we're in — holder self-revocation, and then the public adversarial testnet with the audits. Each phase has a card, each card a human merge.

What this changes for you, if you build agents or verify humans

  1. If you integrate a verifier, the SDKs you would ship against today are the ones running in production. The behaviour will not loosen at mainnet; the cryptography will tighten.
  2. If you are an issuer or a KYC provider, the provider-neutral interface the first issuer uses is the one you would use. Your screeners produce evidence; the issuing authority decides the grade.
  3. If you run agents that pay for things, ZadQ is the surface built for you, and it works today without the network.
  4. If you are waiting for a token, keep waiting. There isn't one, and a launch that starts with the token is the launch we designed MintID not to be.

I closed the July post with a promise to show you the building, not the sketch. This is the building — with the scaffolding still up, labelled as scaffolding. Read the whitepaper, or if you'd rather ask me directly what's behind the private substrate, write to me.

Work with the authors

The CTOs who write this also build

Fractional CTO engagements, AI engineering squads and an AI development platform we install on your codebase in 24 hours. If this piece matched how you think, the conversation is short.

Teams we have embedded engineers in
MintIDCNN InternationalSony Music