Credit without accounts.
Witbitz has no user accounts — access is a link you hold, and credit is a credential you hold. So who takes the payment? Somebody else does. An issuer holds the customer and the payment relationship; the platform validates, meters and settles, and knows neither.
If the shape looks familiar, it is the one card networks use: your bank knows who you are, the merchant sees only that the payment cleared, and the scheme in the middle settles between them without holding either relationship.
The constraint became the business model
Witbitz cannot hold user identity without breaking the thing it sells. The moment the platform holds a durable link between a human and their rooms, it holds a social graph — and that would be the first thing about Witbitz that isn't verifiable.
So it doesn't hold one. It sells the right to hold identity to others. Multiple issuers mean multiple distribution channels, issuers in whatever jurisdiction their customers need, and a platform that is never merchant of record anywhere.
That is a scheme's position rather than a processor's — and it is only worth anything if the separation is real, which is what the honest-status section below is about.
Three roles
What is true today, and what is not
This page is here to be reviewed, so the limits matter more than the pitch.
| A granted credential cannot be linked to a purchase. The issuing tenant id is gone from credentials, replaced by an opaque batch id; the metering ledger no longer records which wallet paid. | live |
| Roles, epochs, single-use spending, redemption. An issuer can be roled, publish a batch key, and have credentials redeemed into wallets — through the documented API. | live |
| Nothing blinds anything yet. Blinding is the client's job and blind-signing the issuer's; neither lives in the platform. Until both exist these are single-use bearer credentials with the right shape — not unlinkable ones. | not yet |
| The epoch→issuer mapping is still platform-held. It sits in its own row precisely so it can be moved out; until it moves, the platform can still resolve which issuer minted a batch. | not yet |
| Purchased credentials stay linkable. The Lemon Squeezy path records the order id, so a bought credential is linkable to a buyer where a granted one is not — unavoidable while LS is merchant of record and holds that identity by law. | by design, for now |
So the claim today is the smaller, real one. The larger claim — that the separation holds mathematically rather than organisationally — waits on blinding and on that mapping moving. We would rather publish the limit than the ambition.
Counts, not links
An issuer sells N credentials in a batch; the platform redeems M of them; the issuer settles on M. Nobody needs to know which — which is what lets the books close while unlinkability is preserved. Double-spend is prevented by a permanent record of spent credentials: permanent deliberately, since an expiring record would make every credential replayable once it lapsed.