Last updated 3 August 2026
my.identity.org.au is the web wallet — the browser portal for your Identity Wallet. Verification itself happens on your phone, because that is where the camera and secure hardware are. Everything after verification — presenting proofs, managing consents, reviewing your history, controlling sessions — works in the portal from any browser.
Signing in
The portal has no passwords. You sign in with a passkey or device-bound credential: a cryptographic key created in your device's secure hardware during setup. Signing in means your device produces a signature — nothing secret is typed, transmitted or stored on a server, so there is nothing for a phishing site to steal.
- Open https://my.identity.org.au — check the address carefully; the portal lives only at that domain.
- Choose sign in, and approve with your device's biometric or screen lock when prompted.
- Sensitive actions — approving a new consent, removing a device — ask you to re-confirm.
The portal will never ask you to type a password, email photos of documents, or sign in from a link in a message. Any of those is a scam — see recognising scams and phishing.
What you can do in the portal
- See your verification level and the credentials behind it.
- Present proofs — age-over, residency, verification level — when a service requests one.
- Review every consent: scope, purpose, expiry — and revoke any of them in one action.
- Read your full consent history, timestamped, including revocations.
- Manage sessions and devices, and sign out everywhere at once.
What stays on your phone
Capture and re-verification — scanning a document, liveness checks, hardware biometrics — are mobile-only, because they need the camera and secure sensors. The portal never holds document images or biometric templates; it works with verification results. If the portal ever appears to ask for your documents, you are not on the real portal.