Every pull request, backed by a verified human.

One GitHub check that shows a real person is behind the PR, even when an agent wrote it.

The four things backed can say

Backed by a verified humanlinked to a unique World ID
Agent PR, backed by a verified humansigned by a registered agent wallet with its operator's track record
Agent, human-backed — unclaimeda real person backs this wallet, no one has claimed it yet
Unverifiedstill welcome — just reviewed after verified ones

How a PR flows

No PR is ever blocked by Backed alone. Verified ones are just reviewed first.

github.com/worldcoin/idkit/pull/412
Add session proof caching #412Open

octodev wants to merge 3 commits into main

needs-verificationlabel removed automatically
backedbot · just now
A real person behind this PR

Verify once with World App to show a real person stands behind this account, without revealing who you are. Verify your account →

vercelDeployment has completed
ci / testSuccessful in 1m 52s
backed / humanUnverified
Merge pull requestother open PRs update too; merge gates still apply
Verify with World ID Scan with World AppOpen verification →

Why this exists

Open source is drowning in slop

Maintainers now review endless AI-generated PRs from throwaway accounts. One check tells them a real person stands behind each one, so they know what to read first.

Protected branches get re-confirmed

For sensitive branches, the same person who verified the account approves each commit from their phone. A face-check tier is on the way.

Agents inherit a human's reputation

Agent PRs are signed, and a real person always backs the wallet. Operators who claim their agents attach their track record — good work builds it, abuse follows them, not a burner account.

Set your rules

Backed works with zero configuration. Pick what you want and commit the file as .github/backed.yml — it only contains what differs from the defaults.

Quick re-verify

The same person's World App approves this exact commit — ~2s

Presence Check

Face check on top of the Orb-level proof — not live yet; gated PRs hold until it ships

A quick re-verification cannot satisfy a Presence Check.
.github/backed.yml
You don't need a file — these are already the defaults.

MCP server — agents sign their own PRs

mcp: backed
attest_pr        sign this PR
check_badge      check this PR's badge
get_repo_policy  read the repo's rules

Set it up once where your agent runs. Every PR it opens signs itself, and it can read a repo's rules before opening one. Approval always happens on a human's phone.

What Backed will never do

Never reads your codeThe app has no contents permission. It can't see a single line of any diff.
Never blocks a PR on its ownBy default the check is informational. Merging only locks if you turn on a gate and require the check in your own branch protection.
Never reveals who anyone isWorld ID proves a unique human, nothing more. Anonymous contributors stay anonymous.
Never judges whether text looks AI-writtenBacked says who stands behind a PR — never how it was made.

Straight answers

Does the badge mean a human wrote the code?

No. It means a real person takes responsibility for it. That's why it says “backed by”, not “written by”.

What stops fake accounts?

Making more accounts doesn't make you more people. All of them trace back to the same World ID, with one reputation and one ban.

Do you learn who I am?

No. We only learn that a real person is behind the account, never who they are. If you're anonymous today, you stay anonymous.

Will it block PRs or read my code?

No. Backed can't read your code and never blocks a PR on its own. Unverified PRs are just reviewed after verified ones unless a repository explicitly enables a gate.

Backed: every pull request, backed by a verified human