Merit · Product · Internal Explainer

Merit ID, explained

One verified identity, connected to everything of value a person holds, and an agent that uses it on their behalf. That is Merit ID. The B2C Super App is one of eight surfaces standing on it, and it is not the point of it. Merit ID is an identity, not a wallet: it carries programmes rather than holding funds, which keeps it outside payment regulation. Every Merit commercial opportunity, including enterprise white-labels hidden behind a client's own brand, runs on this one identity layer. Eight sections carry the argument: the problem, the vision, the moment a consumer feels it, the architecture, the ecosystem, what exists today, the twelve-month roadmap and the network economics. Pricing, the on-chain concept, the regulatory position, the glossary and the detailed flows sit in the appendix, because each of them still needs validation or sign-off.

Owner: Brian Arfi Faridhi · Vision content from Merit product leadership · Companion to The B2C Super App, explained

“Anytime we have a new project, we push everything to Merit ID. At the end of the day, link everything to the Merit ID.”

Julie Barbier, Chief Product Officer

01The problem

Fragmented identity, fragmented value, and a consumer who cannot use either.

Identity does not travel, so value cannot travel either. Both problems have the same root.

Julie shops at Carrefour. She works at Merit and holds Peoppl points. She banks with SAIB and with Al Rajhi. She is Al Fursan Gold and an Optimoji member. She asked one question about all of it: what does that actually give me? She could not answer it, and she runs product for a loyalty company.

One person, six programs, no answer

Each program knows a different part of her. None knows the whole person.

ONE PERSON SIX SEPARATE RECORDS OF HER Julie One human being. Six customer records. Carrefour OWN LOGIN · OWN BALANCE Peoppl, as a Merit employee OWN LOGIN · OWN BALANCE SAIB OWN LOGIN · OWN KYC Al Rajhi OWN LOGIN · OWN KYC Al Fursan Gold MILES SHE CANNOT SPEND HERE Optimoji EXPIRY ARRIVES SILENTLY "What does all of that actually give me?" She cannot answer it. She works in loyalty. A consumer has no chance.
Her own words, from a Merit ID product leadership discussion.
Value destroyed

SAR 2.4B a year

Loyalty points expiring unused in KSA alone. The value is real, it belongs to the consumer, and it is unreachable.

Attention lost

7 to 10 cards, under 3 used

The average Gulf consumer. Every unused card is a program that paid to acquire someone who never came back.

Conversion lost

15 to 20 percent

Of e-commerce checkout conversion, lost to identity and login friction alone, before anyone considers price.

Merit has the same problem from the other side.

Ten clients, ten stacks. Or ten clients, one layer.

Six logins to her. A build cost that repeats with every client, to Merit.

A STACK PER CLIENT ONE LAYER, EVERY CLIENT Client A IDENTITY WALLET INTEGRATION Client B IDENTITY WALLET INTEGRATION Client C IDENTITY WALLET INTEGRATION …and the tenth, again Ten stacks and ten migrations Nothing compounds. The tenth client costs what the first cost. Client A Client B Client C …Client J Merit ID One identity, one consent layer, one value graph, one orchestration. The tenth client is cheaper than the first And every new client makes the network denser for the nine before it.
Stated as a product directive: everything links to Merit ID, and nothing gets its own stack.

Her diagnosis is sharper than the numbers. People do not use loyalty because they do not understand how it works. Julie can fly a family to Bali on points. That takes industry knowledge. A consumer should not need it.

02The vision

One Merit ID connects a person to everything they hold and everything they are entitled to, and an agent uses it on their behalf.

Identity does not travel, so value cannot travel. Merit ID makes identity travel.

Merit ID is the universal identity and value layer of the Merit ecosystem. One bank-grade, KYC-verified identity, connected to everything of value a person holds: points, memberships, status, benefits, discounts, credentials, payment instruments, tickets and access, and corporate entitlements. Loyalty is the first use case, not the scope. The consumer verifies once. The partner never re-verifies. Every Merit product plugs into the same spine instead of rebuilding it.

It answers eight questions about a person. Only the first is an authentication question.

  • Who are you?
  • What value do you hold?
  • What status do you have?
  • What are you entitled to?
  • What can you access?
  • What can you pay with?
  • What benefits can be activated for you?
  • Which data will you share, or which survey will you answer, to build up more value?

That last one already has clients. Kantar and Nielsen are survey companies, and both run Merit storefronts today. Merit also runs bulk redemption for Nielsen. The mechanic is direct: a member answers a survey with their Merit ID and unlocks value for it. No panel to join, and no middleman holding the profile. Consent makes data a trade the member is paid for, priced per person instead of sold in bulk. Flow 1 of the app demo shows the screens: survey, consent, 250 points credited instantly.

“Imagine you could directly answer a survey using your Merit ID and unlock additional value. Your data becomes your new wealth, and you can monetise data at individual level.”

Julie Barbier · Merit ID thread

Everything links to Merit ID. Nothing gets its own stack.

A product directive, not a preference. A new project attaches to the layer instead of getting a parallel build.

The proposition is not "see all your points in one place"

Wallets and aggregators already do that. The differentiated claim is the opposite. You should not have to understand loyalty at all. Merit knows what value you can reach, and uses it for you.

Identity, not a wallet.

Merit ID carries programmes on a person's behalf. It does not hold funds, and it is not a payment instrument. That distinction keeps it outside payment regulation, and it is the reason Merit ID can sit underneath a bank's app, an airline's app or a marketplace without becoming a licensed money product itself.

Every Merit commercial opportunity runs on Merit ID, including enterprise white-labels, where the layer sits behind a client's own brand and a consumer never sees the Merit name. Merit defines one solution per client rather than offering a menu of options, so the client gets a fitted answer instead of a set of choices to configure.

Enterprise employee rewards is a use case, not a different product.

A large employer can run an employee rewards programme on Merit ID. Employees carry a Merit ID employee badge, and the employer runs its own onboarding dashboard first, with the Merit ID layer underneath it. Some employers, the Public Investment Fund among them as an example rather than a commitment, expect on-premises hosting for this kind of deployment.

This is the same identity and value layer used everywhere else in this document, wearing a different front end for a different buyer.

Licensing: the seller is merchant of record.

In the Super App's third-party seller model, the seller is the merchant of record for the sale, and Merit acts as agent. Merit ID is the identity the buyer and seller both trust, not the party taking title to the goods.

03The magic moment

A SAR 400 basket, and Merit finds SAR 91 of value the consumer had forgotten.

Everything else on this page is infrastructure. This is the part a consumer feels, and it is the part that is worth building the infrastructure for. A basket comes to SAR 400. Merit finds points across programs, a coupon she forgot, an entitlement she never claimed and a membership discount, and applies all four in one pass.

Only one identity can do this. To the consumer, those programs are separate companies.

This is also the part investors ask about. It puts Merit ID inside the agentic direction of the market. The agent has to know who you are and what you can reach, and Merit ID is that context.

What the consumer actually sees

One tap at checkout. The agent has already found the value, and the consumer does not have to know where any of it came from.

9:41 MERIT Checkout Basket, 3 items SAR 400.00 MERIT ID We found SAR 91.25 for you From value you already hold. Airline points 200 PTS, EXPIRING − 20.00 Coupon FOUND ON THE WEB − 25.00 Birthday discount NEVER CLAIMED − 30.00 Tennis membership 5 PERCENT − 16.25 You pay SAR 308.75 SAVED SAR 91.25, ABOUT 23 PERCENT Pay now From a trip taken once Points across programs, aggregated. They were going to expire unused. Outside Merit's own data Agentic search on the open internet, not a Merit promotion. An entitlement she already held Issued by a card she carries, and never claimed. Membership as a first-class object Status on the identity, not a coupon code she has to remember. She did not know three of those four existed No research, no apps opened, no codes typed. One screen, one tap. WHAT MAKES IT POSSIBLE: ONE IDENTITY THAT SEES ACROSS FOUR SEPARATE COMPANIES
Illustrative. The benefit types come from a Merit ID product leadership discussion. The amounts are invented to make the arithmetic legible, and are not targets.

A wallet holds value. A marketplace takes payment. Nothing decides.

Julie's framing. The gap between the two halves is where the agent lives, and nobody owns it today.

ONE END A wallet Apple Wallet and its kind. Cards, memberships and passes live here. HOLDS VALUE · DECIDES NOTHING THE OTHER END A marketplace Where value finally gets spent, and where the basket is priced. TAKES PAYMENT · DECIDES NOTHING THE MIDDLE, AND THE GAP Merit ID and the agent It reads what the wallet holds, prices it against the basket, and applies it without being asked. DECIDES READS APPLIES A wallet that only displays leaves the decision with the consumer. A checkout that only charges never knows what the consumer already holds. Merit ID is the only thing standing where both problems meet.
Julie's framing. The positioning is the gap itself, not either end of it.

The same person, the same points, two different apps

A balance screen hands the work back. Coaching does the work and asks for one decision.

WHAT A BALANCE SCREEN DOES WHAT COACHING DOES Your points Al Fursan12,400 miles SAIB3,200 pts Qitaf8,900 pts Peoppl640 pts Now what? Which one expires first? Which one works here? What is it worth? FOUR NUMBERS, NO ANSWER It shows her numbers and wishes her luck. Extracting the value is still a specialist skill she is expected to have. Today ONE THING TO DO Use 200 Al Fursan points They expire on 12 September. Worth SAR 20 on today's basket. Apply it Nothing else needs you The other three are handled, or not worth your attention today. It tells her what to do, once, with the reason and the amount attached. The specialist skill moved into the product.
Same four balances on both screens. The difference is who is expected to do the thinking.
Scope honesty

No build has been sized for this yet. The three-month figure discussed in the session came from external contacts describing what they want to see, which is a signal about timing pressure.

04The architecture

Merit ID as the common spine underneath every Merit product, and what that spine actually holds.

Everything links to Merit ID. Nothing gets its own stack.

Nusuk, NCNP, SAIB, a client marketplace: each one attaches to the identity layer. The reason is not tidiness. It is that the tenth client is then cheaper than the first.

The rule applied, in a live case

SAIB asked for their own marketplace. The answer is a branded link into the same one. Duplicating it buys a migration later, and an internal fight with it.

Identity screening: two populations, two data owners.

Merit ID integrates LSEG World-Check, the Verify product, for sanctions and PEP screening. Two populations sit on the layer: Merit ID members, where Merit owns the data, and partner-programme members, where the partner owns the data. Merit already screens sellers for KYB, PEP and sanctions through Themis, so this extends a control that already exists rather than introducing a new one.

Open design question: whether Merit ID collects the attributes a screening check needs, such as name, date of birth and government ID number, is not yet decided. It sits with whoever owns the population's data, and it is a design choice, not a settled position.

Five layers, and only one of them holds value

Merit ID is not a ledger of other people's points. It is identity, consent and orchestration over value that stays where it is.

WHAT THE LAYER DOES, IN ORDER 01 Identity Verified once, at bank grade. Nafath plus Merit KYC tiers. 02 Connections The programs the member authorises. Consent held once. 03 Value graph Points, memberships, status, entitlements, credentials. 04 Orchestration Find it, reserve it, apply it. The agent runs here. 05 Settlement The only layer where money and points actually move. MERIT ID OWNS THIS LAYER THE ISSUER OWNS WHAT SITS IN IT WHERE THE AGENT RUNS WHO OWNS WHAT Merit ID owns The identity, the consent record, and the orchestration across every program the member connected. The issuer still owns Al Fursan owns the miles. A bank owns its points. A membership issuer owns its entitlement.
The distinction matters technically, commercially and legally. Merit orchestrates access to value it does not hold.

The whole thing in one picture

Issuers and identity sources on the left, verified once. On the right, eight surfaces that consume the layer and none that own it. The B2C Super App is one box among eight.

VERIFIED ONCE THE SPINE NEVER BUILDS IDENTITY AGAIN Banks · BSF, Al Rajhi, ANB Telcos · STC Qitaf Airlines · Al Fursan Marketplaces · Jahez Nafath · national ID Merit ID IDENTITY AND VALUE GRAPH B2C Super App Engage Marketplace LMS · Alamas Point Exchange Membership Client apps Partner checkouts Dashed outline means an identity source rather than a points issuer.
Every arrow in is a partner Merit never verifies twice. Every arrow out is a product that ships without building identity. Nafath is dashed because it feeds identity, not points.

What it buys, one stakeholder at a time

Seven parties, and every one of them is on the network for a different reason. The strip moves on its own. Click a dot to jump straight to one.

Consumers THE PERSON 1 OF 7 PAIN TODAY Seven to ten cards, and fewer than three of them used. Points expire unseen. WHAT MERIT ID CHANGES One identity that carries its own value. Biometric login in about three seconds instead of thirty. Value usable across every connected program. Banks THE ISSUER 2 OF 7 PAIN TODAY KYC repeated per channel, and heavy account-recovery overhead on top. WHAT MERIT ID CHANGES KYC done once and reused everywhere. New revenue when their points get spent on Merit. Telcos THE ISSUER 3 OF 7 PAIN TODAY A huge subscriber base, and almost no loyalty liquidity on it. WHAT MERIT ID CHANGES A signed handoff onboards the base fast. Points become spendable across other programs, not just their own. Airlines THE ISSUER 4 OF 7 PAIN TODAY Miles trapped inside one program, and a member who cannot reach them. WHAT MERIT ID CHANGES Cross-issuer redemption against a single identity. The miles get used, and the liability comes off the balance sheet. Merchants WHERE IT GETS SPENT 5 OF 7 PAIN TODAY 15 to 20 percent of checkout lost to login friction, before price. WHAT MERIT ID CHANGES One-tap verified checkout. mTrust cuts fraud without adding a step for the buyer. Government THE IDENTITY SOURCE 6 OF 7 PAIN TODAY Needs high-assurance identity for national programs. WHAT MERIT ID CHANGES Federated identity through Nafath, for cases like Hajj and Umrah. Merit THE OPERATOR 7 OF 7 PAIN TODAY One-off platforms per client do not compound. Ten clients, ten stacks. WHAT MERIT ID CHANGES A spine every product plugs into. It captures spread, breakage and float on cross-issuer settlement. Consumers THE PERSON 1 OF 7 PAIN TODAY Seven to ten cards, and fewer than three of them used. Points expire unseen. WHAT MERIT ID CHANGES One identity that carries its own value. Biometric login in about three seconds instead of thirty. Value usable across every connected program. CLICK TO SELECT
Every side gives the network something it already has, and gets back something it cannot build alone. That is what makes a connection worth signing.

05The ecosystem

Issuers, identity sources, merchants and Merit products, and the one primitive that connects them.

Four sides, one layer between them

Each side hands the network something it already owns. Each side gets back something it cannot build on its own. Merit ID is what stands in the middle.

IDENTITY SOURCES Nafath Gives high-assurance verification. Gets federated assurance for national programs. ISSUERS Banks, telcos, airlines Gives a live balance, and keeps owning it. Gets KYC reused, and points that finally get spent. MERIT SURFACES, EIGHT OF THEM B2C, Engage, Marketplace, LMS Point Exchange, Membership, client apps, partner checkouts. All consume the layer. None owns it. MERCHANTS Jahez first Gives a checkout the agent can act on. Gets one-tap verified buyers, and demand it could not reach. GIVES GETS Merit ID IDENTITY AND VALUE GRAPH Holds none of it. AND EVERY SIDE CONNECTS THE SAME WAY: ONE PRIMITIVE, FOUR STEPS STEP 1 Permission The member agrees. STEP 2 Verify OTP or signed handoff. STEP 3 Token Merit never asks again. STEP 4 Live balance Read on demand. STEPS 1 AND 2 COST EFFORT ONCE STEPS 3 AND 4 KEEP PAYING OUT, FOR AS LONG AS THE MEMBER STAYS
Merit already holds B2B contracts with many of these partners, so the ask is often to connect an existing partner. The flow in full is appendix A6.

Issuer connection status

The technical connection, not the commercial relationship. A pill marks a build state, not a deal stage.

IssuerTypeConnectionRole
PeopplMerit's own pointsLIVE IN APPThe only issuer a user can actually see today.
BSFBankCONNECTEDTechnical connection established, not yet consumer-visible.
Al RajhiBankCONNECTEDTechnical connection established, not yet consumer-visible.
ANBBankCONNECTEDTechnical connection established, not yet consumer-visible.
STC QitafTelcoSIGNED HANDOFFThe connection pattern the rest of the network reuses.
SAIBBankIN PROGRESSA bank-level connection, and a candidate for the deeper embedded-finance optionality in appendix A3.
AirlinesAirlineNOT STARTEDThe hardest counterparty type to open with, so integration starts later by design.
Connected means a technical connection exists, not that a consumer can see it in the app. Only Peoppl is visible in the product today, which is the single biggest gap between this page and reality.
The wedge

Jahez, then everyone

No merchant refuses Jahez. As its checkout fills up with loyalty options, Merit ID becomes the obvious way to simplify it, and the rest of the network follows the traffic.

The unlock

Enter as public sector

Approaching an issuer as a Merit B2C product invites a negotiation. Approaching under a national initiative such as NCNP or Nusuk does not. It is very hard for a merchant to refuse a public-sector programme.

The trade

Terms are secondary

Accept a weak commercial deal to get connected. Per-deal margin is recoverable later; a competitor getting there first is not.

06What exists today

The starting position, stated plainly, because a vision that overstates the present tense stops being useful the first time somebody checks.

Merit does not start at zero

The legacy platform already connects dozens of programs. That estate is real revenue and real relationships. What is new is one identity layer under all of them. Only Peoppl is visible on that new layer today. The table shows the new layer only.

CapabilityStateDetail
Identity system of recordLIVEOff-chain. Auth, KYC tiers, sessions and security all built.
Merit ID appLIVE, UNTESTEDIn the KSA and UAE App Stores. Deliberately not promoted, still in final testing.
Issuer connection journeyBUILTPermission, OTP, token, live balance reads. Working end to end.
Connected issuers visible in appONEPeoppl only. The multi-issuer experience is not yet visible to any user.
Bulk identity creationBUILTProven on the Gift Global migration, 1,341 users.
In-app marketplaceINCOMPLETECannot yet replace Gift Global, which is what gates decommissioning it.
mTrust ScoreIN BUILDGeneral availability not yet scheduled.
Membership featureBRD DRAFTv0.1, awaiting decisions on tiers, pricing and first program.
AI agent at checkoutCONCEPTNo build sized yet. The urgency is an external expectation, not an internal commitment.
On-chain credentialCONCEPTA concept, with nothing built and nothing committed. The closed-loop position is a design intent awaiting external counsel, per jurisdiction.
Two things to fix before this is shown widely

Gift Global is a known security exposure and stays live until the Merit ID marketplace can replace it. And the app is region-locked to the KSA and UAE stores. Colleagues elsewhere cannot install it. The CPO in France is one of them. Neither is fatal. Both are embarrassing to discover in front of a partner.

07The twelve-month roadmap

Now, connect, orchestrate, intelligence. Each stage is useful on its own, and each one is visible to a consumer.

Twelve months, and what a consumer can see at each step

Every stage ships something visible. A stage that a consumer cannot see is a stage that cannot be checked.

NOW Identity works Auth, KYC tiers, sessions. The issuer connection journey, end to end. Bulk migration, proven. SEES: PEOPPL ONLY CONNECT The wallet fills up Multi-issuer wallet, Membership, marketplace, Point Exchange, mTrust. SEES: EVERY BALANCE ORCHESTRATE Value gets applied At Merit checkouts first, then at partner checkouts. SEES: A LOWER PRICE INTELLIGENCE The agent decides Across every program the member holds. Universal partner checkout, plus wider ecosystem work. SEES: NOTHING TO DO OPTIONAL FUTURE · NOT SCHEDULED Verifiable credentials and on-chain settlement. Embedded finance and tokenisation. Each one waits on technical, regulatory and legal validation. None of them is a commitment.
The cadence is the commitment. Once a team is dedicated to Merit ID, ship something new every month.
The weakness this has to beat

Merit builds things and then stops enhancing them. That habit turns a platform into a collection of finished projects. The answer is a cadence, not a date. Ship something new every month.

08Network economics and the moat

Every new connection makes every existing one worth more. That is the reason to build it, and the reason the window matters.

Six layers to earn on, and one of them compounds. Identity and API fees, partner integration, transaction and orchestration economics, Point Exchange economics, mTrust, premium capabilities.

Willingness to pay is not validated. The indicative price bands sit in appendix A1 and are not a commitment.

Adding the eighth issuer is worth more than adding the second

Seats grow one at a time. Connections grow with the square of the network. That gap is the moat.

EVERY PAIR OF CONNECTED ISSUERS IS A REDEMPTION ROUTE MERIT CAN SETTLE 3 issuers 3 CONNECTIONS 5 issuers 10 CONNECTIONS 8 issuers 28 CONNECTIONS
A competitor has to rebuild the connections, not just the product.

Why the window matters now

Competition

Someone else is building this

Sanabil is working on something in the same space. Merit's advantage is Jahez, and that advantage is fresh rather than permanent.

Exposure

The vision is already outside the building

It has to be discussed for investment reasons, which means the idea is in the open while it is unbuilt. An idea described but not shipped is one somebody else can ship.

Demand

The pull is specific

Contacts across Visa, Google Pay and Apple Pay in the US described this as the next thing they want to see. That is who is applying the timing pressure.

Where the margin comes from

~85% GM

Identity, verification, mTrust

Behaves like pure SaaS. Cost of goods is auth infrastructure, scoring compute and observability.

55–65% GM

Issuer integration fees

Lower, because onboarding services and data mapping are bundled in. Productising the onboarding lifts it.

Compounds

Cross-issuer spread and FX

High margin, and it grows with network density rather than with seat count. This is the only line that gets structurally better the longer the network runs.

Per-seat revenue scales with customers. Settlement spread scales with the connections between them. That is a much steeper curve.

AAppendix

Everything from here waits on validation or sign-off. Do not quote any of it as a Merit position.

A1 pricing, pending commercial sign-off. A2 the on-chain concept, pending counsel. A3 embedded finance, as optionality. A4 roles and definitions. A5 glossary. A6 the issuer connection flow.

A1How it earns, and the price that is not set yet

Six monetisation layers, and an indicative band that has not been tested with a single issuer.

Merit ID sells to partners on verification cost avoided and conversion recovered. There are six monetisation layers to work with: identity and API fees, partner integration, transaction and orchestration economics, Point Exchange economics, mTrust, and premium capabilities. The pricing principle is deliberate. Set the per-identity fee below what the partner already spends re-verifying and re-acquiring that user. Merit ID then reads as a saving, not a new line item.

The bands below are not a price list

Willingness to pay has not been tested with a single issuer. Anchoring a price before that test sets the ceiling for everyone who reads it, so these numbers stay internal, stay indicative, and need commercial sign-off before any external use. Validate with two or three issuers first, then set the bands.

Indicative price per active Merit ID, per month

Volume bands. One measure on one scale, so one hue darkening with volume.

$0.40 $0.25 $0.15 StarterTO 10K Growth10K–100K Scale100K–1M ENTERPRISE, ABOVE 1M ACTIVE IDS, IS PRICED ON APPLICATION
Indicative and not yet validated with the commercial team. Auth0's published per-MAU CIAM pricing is the external anchor these bands were set against.

A2Potential on-chain architecture

Subject to technical, regulatory and legal validation. Nothing here is built and nothing is committed.

Three phases

Phase 3 is the one that changes the character of the thing, and it is a phase Merit can schedule on its own engineering timeline.

NOW NEAR TERM LATER Phase 0 · Internal Merit's own roughly 100 staff become the first ID holders. IDENTITY: A1, MERIT-MANAGED Proves the concept without waiting on the B2C launch. Phase 1–2 · Alliance External issuers join by signed handoff and prepaid settlement. CONNECTION: B2 API Onboards in days. Point Exchange runs off-chain. Phase 3 · On-chain Verifiable credential anchored on Avalanche mainnet. IDENTITY: A2, CRYPTOGRAPHIC Partners verify without calling Merit at all.
Potential future architecture, subject to technical, regulatory and legal validation. Removing per-transaction Merit permission is what would turn a platform into a network. Nothing here is built or committed, and the phase 3 design has no formal opinion from external counsel behind it yet.
The intended regulatory position, and what still has to be validated

The design intent is that Merit operates as a Technology Service Provider, not a Virtual Asset Service Provider. That is a design intent, not a legal conclusion. External counsel has not signed off these propositions in each relevant jurisdiction. Until they do, present none of this as settled. $MERIT would be a closed-loop utility token. It would not be withdrawable to an external wallet, would not trade on a public exchange, and would be spendable only inside the Merit merchant network. The interface would expose no fiat off-ramp, and a user who wants fiat would be handed to a licensed VASP partner. Nothing of this is built. The precedent people cite is airline miles and Starbucks Stars: real value, not money transmission, because it is restricted to a defined ecosystem. A precedent is not an opinion from counsel, and blockchain only gets built here if it demonstrably improves interoperability, verification or settlement.

The token would have to be transfer-restricted at token level. A freely transferable token can reach a public exchange, which forms a de-facto off-ramp Merit does not control. Closed-loop has to be engineered in, not assumed. Mainnet is public, so the Merit ID to wallet mapping stays off-chain and encrypted.

A3Beyond points, as optionality

Interesting future use cases. None of them is an established Merit ID capability today.

Embedded finance

Lending against aggregated value

Optionality, not a capability. If Merit ID can see what a member holds, a lender could in principle advance against it. Untested, unbuilt and regulated. It is one reason SAIB wants equity, and the aggregation is what gets built first.

Tokenisation

Liquidity for loyalty liabilities

Also optionality. Points are a liability on an issuer's balance sheet, and liquidity against them would turn loyalty into a financial product. Merit does not have to become a financial institution to have an enormous opportunity.

Data

mTrust as a product

The 1 to 100 trust score exists for Merit's own risk decisions, but it sells standalone to issuers and financial institutions as a risk-signal API. General availability is not yet scheduled.

Membership, the capability nobody expected to be reusable

The premium membership shaped for Riyadah was originally going to be a standalone microsite. Julie's direction was that it should not be. Membership is a layer of status, entitlements and a digital credential sitting on top of an identity, and Merit ID already owns the identity. So Membership became a native Merit ID feature: tiers, a digital card in Apple and Google Wallet, and a benefits engine that any program can configure. Riyadah is the first tenant, not the only one. It is also what makes the tennis federation discount in section 03 mechanically possible.

A4Who is who, and the words that trip people up

The government identity source separates this from an auth product. The issuer separates it from a loyalty engine.

Supply of value
Issuer
Banks, telcos, airlines, marketplaces. They hold idle point liability and a customer base they have already verified. They connect once and stop re-verifying.
Source of truth
Identity provider
Nafath for Saudi national identity. Feeds high-assurance verification into Merit ID for cases like Hajj and Umrah where the bar is a government bar.
Middle
Merit ID
Owns the verified identity, the consent layer, the entitlement graph, the trust score and the orchestration. It does not own the underlying value: the issuer still owns its points, its miles and its entitlements. Everything else in the company plugs into it.
The user
Member
A retail consumer holding a Merit ID. Distinct from a User, a corporate admin who logs into dashboards. Members have Merit ID; Users do not.
Consumes identity
Program
B2C Super App, a client marketplace, an LMS tenant, a membership like Riyadah. Issues status and benefits on top of an identity it did not have to build.
The distinction that trips people up

Merit ID separates two things. A Member is a retail consumer who holds a Merit ID. A User is a merchant or corporate admin on normal corporate auth. Only Members have a Merit ID. In a spec the two can look interchangeable. They are not.

A5Glossary

Terms that appear across the Merit ID specs and mean something specific.

Merit ID
A unique handle, for example @brian, mapped to a verified phone, email and KYC status. The identity itself, not the app that surfaces it.
Member vs User
A Member is a retail consumer holding a Merit ID. A User is a corporate or merchant admin who signs into dashboards through normal corporate auth. Only Members have a Merit ID.
mTrust Score
A 1 to 100 fraud and transaction-integrity score computed from in-ecosystem behaviour. Drives KYC tier limits and velocity caps, and sells standalone as a risk API.
A1 and A2
Identity models. A1 is Merit-managed and off-chain: partners verify by calling Merit, so Merit is the gatekeeper. A2 is an on-chain verifiable credential: partners verify cryptographically without Merit in the loop.
B1 and B2
Partner connection models. B2 is a B2B API with a signed handoff and a prepaid deposit, onboarding in days. B1 is a strategic anchor partner interacting natively on mainnet.
Signed handoff
The proven STC Qitaf pattern. The issuer sends one identifier such as a phone number, Merit enriches the record once, and every later transaction is frictionless. It is effectively a primitive version of the A2 credential.
Nafath
The Saudi national identity API. An identity source rather than a points issuer, used where a government level of assurance is required, such as Hajj and Umrah programs.
Transfer-restricted token
A token that can only move between allowlisted addresses, or cannot move at all. The mechanism intended to keep the on-chain phase closed-loop. Whether that places it outside virtual-asset regulation is a question for external counsel, and no opinion has been given.
Point Exchange
The any-to-any point conversion engine, with a rate table built from a peg plus a Merit spread. The component that makes cross-issuer redemption possible.

A6How an issuer connects, in full

The flow behind section 05. It is already built and working, and it is the primitive the whole network is made of.

Permission, then token, then live balance

Four steps. After the first three, every later transaction is frictionless, because Merit holds a token rather than asking again.

STEP 1 Issuer authorises The points owner agrees to expose balances to Merit. STEP 2 User authenticates Usually a one-time password on the issuer's own channel. STEP 3 Merit holds a token The consent becomes durable. No repeat permission needed. STEP 4 Live balance reads Spending re-authenticates, reading does not. ONE-TIME COST PERMANENT BENEFIT
The asymmetry is the whole point. Steps one and two cost effort once. Steps three and four keep paying out for as long as the member stays.
Why this is easier than it sounds

Merit already holds contracts with many of these partners from the B2B side of the business. In several cases the remaining work is asking an existing partner to connect, not selling a stranger on the idea. Airlines were deliberately left until later as the hardest counterparties to start with.