Onchain Attestations evaluated across revocation and expiry semantics, issuer permissioning and identity, verifiable chain deployments, and cost per attestation.
Sign Protocol
#1 of 7 · published ranking
Sign Protocol
81ChainChoice Score
4199
Why it leads
Best in the pool on revocation and expiry (10/10; next 9/10)
7onchain attestations · sorted by chainchoice score
ranked before any payout data is seen
#1 overall·computed before any payout data is seenOverall
Sign Protocol
Sign Protocol
Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets.
Leads the pool on Revocation and expiry semantics
81ChainChoice Score · first of 7
4199
Catalog strengths
Revocation and expiry semanticsVerifiable chain deploymentsCost per attestation
Why it leads
Best in the pool on revocation and expiry (10/10; next 9/10)
1 point ahead of Ethereum Attestation Service (EAS): +2.0 pts revocation and expiry
Provider states broad availability
Evidence
4/4
criteria scored · 4 receipts quoted
Margin
+1
over Ethereum Attestation Service (EAS), ranked #02
Rank stability
One-point
a ±1 reread of "Revocation and expiry semantics" would crown Ethereum Attestation Service (EAS)
Tradeoff
−3
Issuer permissioning and identity — behind this pool's best
Jurisdiction
Global
no restricted market on record
Score breakdowntick = pool best
Revocation and expiry10/10
Issuer accountability6/10
Deployment verifiability9/10
Issuance cost8/10
Ranking-blind · a guided run tailors this to your size, custody & jurisdiction
#ProviderScoreEvidenceKey strengths
2−1
ET
Ethereum Attestation Service (EAS)
Revocation and expiry semanticsVerifiable chain deployments
3−1
VE
Verax Attestation Registry
Issuer permissioning and identityRevocation and expiry semantics
4−8
PR
Privado ID (formerly Polygon ID)
Revocation and expiry semanticsIssuer permissioning and identity
5−3
Coinbase Verifications
Coinbase Verifications
Issuer permissioning and identityCost per attestation
6−3
Solana Attestation Service (SAS)
Solana Attestation Service (SAS)
Issuer permissioning and identityCost per attestation
7−1
HU
Human Passport (formerly Gitcoin Passport)
Verifiable chain deploymentsIssuer permissioning and identity
Ranking-blind — order computed before any payout data is joined
Below the table
How this ranking works
Everything the table draws on continues here: how firm the #1 is, the per-criterion arithmetic behind each score, who pays ChainChoice, and the full guide to choosing.
Direct answer
What is the best onchain attestations in 2026?
Sign Protocol ranks #1 overall for onchain attestations on ChainChoice. Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets. It holds that rank under an affiliate-blind methodology scored across 4 published, weighted criteria — the code that ranks providers physically cannot read affiliate payouts (CI-enforced), so a payout can't move a rank. The verdict re-computes on every fee change, incident, or regulatory action; full reasoning and the audit receipt are below.
Best picks
Best onchain attestations in 2026
Weighted on revocation and expiry semantics (32), issuer permissioning and identity (26), verifiable chain deployments (24), and cost per attestation (18). Revocation carries the most weight because it is where the category breaks quietly: Solana Attestation Service revokes by DELETING - close_attestation.rs calls attestation_info.close(), and the string "revok" appears zero times in the Attestation struct source, so after revocation the record does not exist and a consumer cannot tell a withdrawn credential from one that was never issued. The rent refund flows to whoever closes it, which means the economics reward erasing the evidence.
Best overall
Sign Protocol
Sign Protocol
Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets.
Data checked Sep 2026
Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets. Strongest on revocation and expiry semantics (10/10): Sign Protocol keeps a revoked attestation onchain with a revoked flag and revocation timestamp, emits the revocation reason, and enforces expiry through validUntil capped by the schema's maxValidFor. Revocability is set per schema, and offchain attestations can be revoked onchain with a reason. Weakest on issuer permissioning and identity (6/10): Sign Protocol records the attester, who must be the caller of attest() and the only party able to revoke, but issuance is open to any address and the protocol stores no issuer name or allowlist; gating is left to optional schema hooks. Published price: "To fund the account balance to pay for API key usage, you can purchase credits with USDC (1 USDC = 100 Credits)." — this priced service pays for decentralized storage uploads (a base fee of "0.01" Credits per upload on Arweave, BNB Greenfield and IPFS plus a…
Best for: Revocation and expiry semantics — 10/10
Why this score4 published criteria · leads 2 of 4
Published criterionWtScore, and the best hereGap/10Pts
Revocation and expiry semantics7.7·1010.2
Issuer permissioning and identity6.2−365.0
Verifiable chain deployments5.8·96.9
Cost per attestation4.3−184.6
Σ methodology points26.8/32
Each bar is the score on that criterion’s own 0–10 scale, never rescaled to the pool. The dark line is the best any product here reached on that axis. Wt is the most the criterion can add to the 86-point weighted total. Pts is weight × score × 32; the sum is the methodology score, and each weighted point behind the leader costs 2.6 on the displayed score. how these are weighted
Considered and not ranked
2 products we looked at and left out
A shortlist is only honest if it says who it turned away. Each of these was assessed against the same published criteria as the ranked table and excluded for a stated reason — not overlooked.
We assessed 6 products here and rank 4 — 67% of what we looked at. That share is of the products we assessed, not of the category: how many exist is not something we can count, so we do not claim a number for it.
World ID / Worldcoin· No longer operatingOptimism Attestation Station
Why it ranks first
Why Sign Protocol leads this category right now
Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets. Strongest on revocation and expiry semantics (10/10): Sign Protocol keeps a revoked attestation onchain with a revoked flag and revocation timestamp, emits the revocation reason, and enforces expiry through validUntil capped by the schema's maxValidFor. Revocability is set per schema, and offchain attestations can be revoked onchain with a reason. Weakest on issuer permissioning and identity (6/10): Sign Protocol records the attester, who must be the caller of attest() and the only party able to revoke, but issuance is open to any address and the protocol stores no issuer name or allowlist; gating is left to optional schema hooks. Published price: "To fund the account balance to pay for API key usage, you can purchase credits with USDC (1 USDC = 100 Credits)." — this priced service pays for decentralized storage uploads (a base fee of "0.01" Credits per upload on Arweave, BNB Greenfield and IPFS plus a…
Best for
Revocation and expiry semantics — 10/10
Main tradeoff
Every maintained mainnet deployment is an upgradeable proxy owned by one address, 0xAE45849165E17Dc555B8264dD4Ae01a3F42344e2, and eth_getCode for that address returned exactly "0x" on both Ethereum and Base on 2026-08-07 — it is an externally-owned account, not a multisig. One private key can therefore replace the attestation logic on nine mainnets at once. Separately, the documentation has been reframed around S.I.G.N.: the docs index at docs.sign.global/llms.txt is titled "# Sovereign Infrastructure for Global Nations" and describes "S.I.G.N. is sovereign-grade digital infrastructure for national systems of money, identity, and capital. Sign Protocol provides the shared evidence layer used across deployments.", so a buyer integrating the developer stack is now a secondary audience.
Verify before signup
"To fund the account balance to pay for API key usage, you can purchase credits with USDC (1 USDC = 100 Credits)." — this priced service pays for decentralized storage uploads (a base fee of "0.01" Credits per upload on Arweave, BNB Greenfield and IPFS plus a per-byte size fee, with the caveat "Please note the above fees may be adjusted without notice. All fee units are in Credits."). No protocol fee is documented for onchain attest() or revoke(); the ISP reference only offers payable variants for when a schema hook the schema owner attached expects payment, and offchain attestation via attestOffchain carries no documented charge. (Sign Developer Platform page, docs.sign.global/for-builders/sdp.md, fetched 2026-09-27)
Recommendation summary
What should decide this category
When a claim is withdrawn, can a consumer still see that it existed?
Who is permitted to issue, and can you establish who signed?
Are the deployments real - contract addresses you can check on an explorer?
Quick picks
Strong options in this category
Start with the lead choice first, then use the shortlist only if you still need a challenger or stronger fit for a specific setup.
Best overall
Sign Protocol
Sign Protocol
Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets.
Permissionless omnichain attestation protocol with schema-enforced validity caps and reasoned revocation, deployed as upgradeable proxies on nine maintained EVM mainnets. Strongest on revocation and expiry semantics (10/10): Sign Protocol keeps a revoked attestation onchain with a revoked flag and revocation timestamp, emits the revocation reason, and enforces expiry through validUntil capped by the schema's maxValidFor. Revocability is set per schema, and offchain attestations can be revoked onchain with a reason. Weakest on issuer permissioning and identity (6/10): Sign Protocol records the attester, who must be the caller of attest() and the only party able to revoke, but issuance is open to any address and the protocol stores no issuer name or allowlist; gating is left to optional schema hooks. Published price: "To fund the account balance to pay for API key usage, you can purchase credits with USDC (1 USDC = 100 Credits)." — this priced service pays for decentralized storage uploads (a base fee of "0.01" Credits per upload on Arweave, BNB Greenfield and IPFS plus a…
Best for: Revocation and expiry semantics — 10/10
Revocation and expiry semantics · 32%
10/10
Issuer permissioning and identity · 26%
6/10
Verifiable chain deployments · 24%
9/10
Cost per attestation · 18%
8/10
Quick pick
ET
Ethereum Attestation Service (EAS)
Permissionless onchain and offchain attestation registry with a schema registry, deployed on 11 EVM mainnets and shipped as an OP Stack predeploy.
Permissionless onchain and offchain attestation registry with a schema registry, deployed on 11 EVM mainnets and shipped as an OP Stack predeploy. Strongest on revocation and expiry semantics (9/10): EAS keeps a revoked attestation onchain with its revocation time, a per-attestation revocable flag and an expiry field, so a revoked claim stays distinguishable from one never issued. No revocation reason is stored, and the docs leave offchain revocations to separate management. Weakest on issuer permissioning and identity (6/10): Issuance on EAS is open to any address. Each attestation records and indexes the signing address, and only that attester can revoke it, but the protocol stores no issuer name or allowlist; unless a schema owner attaches a resolver, the consumer decides which addresses to trust. Published price: "EAS is a free service. However, when making onchain attestations, users will incur gas fees, which vary based on network activity, attestation complexity, and the specific chain used.
Best for: Revocation and expiry semantics — 9/10
Revocation and expiry semantics · 32%
9/10
Issuer permissioning and identity · 26%
6/10
Verifiable chain deployments · 24%
9/10
Cost per attestation · 18%
9/10
Quick pick
VE
Verax Attestation Registry
Consensys-maintained shared attestation registry on four EVM mainnets where issuance runs through named, registry-allowlisted Portal contracts.
Consensys-maintained shared attestation registry on four EVM mainnets where issuance runs through named, registry-allowlisted Portal contracts. Strongest on issuer permissioning and identity (9/10): Verax admits issuers through an owner-held allowlist and routes every attestation through a registered Portal that must carry a name and an owner name; only the issuing Portal can revoke. The owner name is self-declared and one registry owner holds the allowlist. Weakest on cost per attestation (7/10): Verax publishes no protocol fee; the issuer pays gas plus a one-time Portal deployment. There is no offchain path and no published per-attestation cost, and an optional FeeModule lets a Portal creator charge a fee on attestations made through that Portal. Published price: No protocol fee is published in the README or the issuer documentation; the README's only price-bearing line is its licence badge, "[](./LICENSE)", so the registry itself costs nothing and the issuer…
Best for: Issuer permissioning and identity — 9/10
Revocation and expiry semantics · 32%
8/10
Issuer permissioning and identity · 26%
9/10
Verifiable chain deployments · 24%
8/10
Cost per attestation · 18%
7/10
Quick pick
PR
Privado ID (formerly Polygon ID)
Self-hosted issuer-node stack for W3C verifiable credentials with zero-knowledge presentation and three selectable revocation-status transports, anchored to CREATE2 State contracts on five listed networks, one of which (Polygon zkEVM) has produced no block since 2026-07-03.
Self-hosted issuer-node stack for W3C verifiable credentials with zero-knowledge presentation and three selectable revocation-status transports, anchored to CREATE2 State contracts on five listed networks, one of which (Polygon zkEVM) has produced no block since 2026-07-03. Strongest on revocation and expiry semantics (7/10): Privado ID offers three revocation-status transports, one of which keeps revocation onchain even when the issuer node is offline, and its State contracts timestamp expirations. The issuer picks the transport, so onchain revocation is not guaranteed, and no revocation reason is recorded. Weakest on cost per attestation (6/10): Privado ID publishes no price list and no protocol fee. Issuers run a self-hosted node (Vault, Redis, Postgres) whose cost depends on the chosen cloud infrastructure; signature credentials are issued offchain without per-credential gas, and published gas figures cover verification only. Published price: No price list is published — www.privado.id/pricing and privado.id/pricing both returned HTTP 404 on 2026-09-27.
Best for: Revocation and expiry semantics — 7/10
Revocation and expiry semantics · 32%
7/10
Issuer permissioning and identity · 26%
7/10
Verifiable chain deployments · 24%
7/10
Cost per attestation · 18%
6/10
Frequently asked
Questions people ask before choosing onchain attestations
What happens when an attestation is revoked?
It depends on the system, and the difference is the most consequential thing in this category. EAS records a revocationTime, so a consumer reading the record sees a claim that was made and later withdrawn. Solana Attestation Service instead closes the account: close_attestation.rs calls attestation_info.close(), the Attestation struct source contains no occurrence of "revok", and the rent refund goes to whoever performs the closure. After revocation there is nothing to read, so a withdrawn credential and one that was never issued are indistinguishable - and the party who erases it is paid to do so. This is the finding most likely to break a compliance integration silently, because nothing errors; the claim simply stops being there.
Can I rely on a big-name attestation for compliance?
Read the issuer's own terms first. Coinbase Verifications is the closest thing to institutional KYC in this pool and its integration README says the attestation "is for informational purposes only and should not be relied upon by you or any third party for any legal, compliance, or contractual purpose", adding that Coinbase "does not represent, warrant or guarantee that the information contained in any attestation or represented thereby is complete, accurate, or current." The schemas are revocable onchain - verified by eth_call to the Base SchemaRegistry predeploy, returning revocable true for all three - yet the words "revoke", "revocation", "expiry" and "expiration" appear zero times in that 10,341-byte README. The capability exists and the documentation never tells an integrator how it behaves.
Are these deployments as decentralised as they look?
Not always, and the check is cheap. Sign Protocol's maintained deployments across nine mainnets are upgradeable proxies owned by a single address: eth_getCode for that owner returned exactly "0x" on both Ethereum and Base, meaning an externally owned account rather than a multisig. All nine proxies return identical bytecode, so one key can replace attestation logic on nine chains at once. Separately, cost is worth checking against the chain rather than the price list: Human Passport charges $2 to write an attestation whose measured onchain cost the same day on the same L2 was $0.004319, a 463x markup, for a score that carries no expiry field - "Onchain scores do not have an explicit expiry date associated with them."
Free advisor·No signup needed
Still unsure? Get your best onchain attestations pick
Answer a few quick questions and get one clear recommendation based on how you actually plan to use crypto — then review the evidence before deciding.
No signup·Free first pass · Private·No spam · No account
Not financial advice · Independent · Always do your own research
Browse this network
How this ranking is built
Reviewed on revocation and expiry semantics, issuer permissioning and identity, verifiable chain deployments, and cost per attestation.
Data checked Sep 2026 · Independent rankings · We show our work
Not financial advice · For informational purposes only · Always do your own research
//Analytics consent·GDPR · ePrivacy · TTDSG
ChainChoice measures page views and conversions with two cookieless, EU-hosted services: Plausible and Cloudflare Web Analytics. Nothing loads until you accept, and rankings are identical either way.ChainChoice measures how the engine is used — page views, conversions, referrer — through two cookieless, EU-hosted services: Plausible and Cloudflare Web Analytics. No advertising cookies, no cross-site profile, no data resale. Neither script loads until you accept, and rankings are identical whether you accept or decline.