Use
'anyone' when third parties must verify the result, 'self' for records only your app and user read, and a specific key for pairwise data.
Read the identity key
Derive an app-scoped key
Sign and verify data
Encrypt a record
Authenticate a record with HMAC
Certificates
Acquisition depends on your certifier’s BRC-52 flow. Once the user holds a certificate, reading and disclosing it is portable:proveCertificate prompts with the exact fields being revealed, so request the fewest that your check requires.