Merit · Product · Internal Explainer

Merit ID, explained

The B2C Super App aggregates a consumer's points into one wallet. Merit ID is the layer underneath it that makes that possible, and it does not stop at points. One verified identity that carries value, status and trust across every Merit product and every partner who plugs in. This page starts at the one-minute version and ends at an honest status.

Owner: Brian Arfi Faridhi · Drafted 6 Aug 2026 · Vision content from the ELM session, 6 Aug 2026 · Companion to The B2C Super App, explained

“Anytime we have a new project, we push everything to Merit ID. At the end of the day, link everything to the Merit ID.”

Julie Barbier, Chief Product Officer · ELM session, 6 August 2026

01In one minute

If you only read one section, read this one.

A Gulf consumer holds seven to ten loyalty cards and actively uses fewer than three. Every platform makes them sign up again and prove who they are again. In KSA alone an estimated SAR 2.4B of points expire unused every year, and identity friction costs e-commerce merchants an estimated 15 to 20 percent of checkout conversion. Both problems have the same root: identity does not travel, so value cannot travel either.

Merit ID is the layer that makes identity travel. One bank-grade, KYC-verified identity, a loyalty passport, that a consumer carries across every Merit storefront, app and partner program. The consumer verifies once. The partner never re-verifies. Every Merit product plugs into the same spine instead of rebuilding it.

The B2C Super App is the most visible thing standing on Merit ID, but it is not the point of it. Merit ID is what stops Merit building a bespoke platform per client and starts it building a network where each new partner makes the next one easier to sign.

The whole thing in one picture

Issuers and identity sources on the left, verified once. Merit products on the right, none of which build identity themselves. Merit ID is the only thing in the middle.

VERIFIED ONCE THE SPINE NEVER BUILDS IDENTITY AGAIN Banks · BSF, Al Rajhi, ANB Telcos · STC Qitaf Airlines · Al Fursan Marketplaces · Jahez Nafath · national ID Merit ID ONE IDENTITY + mTRUST B2C Super App Marketplace LMS · Alamas Point Exchange Dashed outline means an identity source rather than a points issuer.
Every arrow in is a partner Merit does not have to verify twice. Every arrow out is a product that ships without building identity again. Nafath is drawn dashed because it feeds identity, not points.
Status

System of record is live

Off-chain. Auth, KYC tiers, sessions and security are built and running. Bulk creation is proven on the Gift Global migration, 1,341 users.

Reality check

One issuer connected in the app

Peoppl only. The connection journey works end to end, but a user cannot yet see the multi-issuer experience this page describes.

Direction

Every project links here

Stated as a directive on 6 August, not a preference. Nusuk, NCNP, SAIB and every future program attach to Merit ID rather than getting their own stack.

02Who is who

Five roles. The one that separates Merit ID from an authentication product is the government identity source, and the one that separates it from a loyalty engine is the issuer.

Supply of value
Issuer
Banks, telcos, airlines, marketplaces. They hold idle point liability and a customer base they have already verified. They connect once and stop re-verifying.
Source of truth
Identity provider
Nafath for Saudi national identity. Feeds high-assurance verification into Merit ID for cases like Hajj and Umrah where the bar is a government bar.
Middle
Merit ID
Owns the verified identity, the unified ledger, the trust score and the consent layer. Everything else in the company plugs into it.
The user
Member
A retail consumer holding a Merit ID. Distinct from a User, a corporate admin who logs into dashboards. Members have Merit ID; Users do not.
Consumes identity
Program
B2C Super App, a client marketplace, an LMS tenant, a membership like Riyadah. Issues status and benefits on top of an identity it did not have to build.
The distinction that trips people up

Merit ID separates the Member, a retail consumer who holds a Merit ID, from the User, a merchant or corporate admin who signs into a dashboard through normal corporate auth. Only Members have a Merit ID. If you are reading a spec and the two seem interchangeable, they are not.

03Why loyalty fails, and why that is an identity problem

The market numbers say value is being destroyed. Julie's account of her own wallet says why.

Value destroyed

SAR 2.4B a year

Loyalty points expiring unused in KSA alone. The value is real, it belongs to the consumer, and it is unreachable.

Attention lost

7 to 10 cards, under 3 used

The average Gulf consumer. Every unused card is a program that paid to acquire someone who never came back.

Conversion lost

15 to 20 percent

Of e-commerce checkout conversion, lost to identity and login friction alone, before anyone considers price.

Julie described her own position as a consumer: a mother of three shopping at Carrefour, a Merit employee with her own points, an SAIB customer, an Al Rajhi customer, Al Fursan Gold, and an Optimoji member. Her question was not rhetorical. What does all of that actually give her? She cannot tell, because every piece of it is somewhere else.

Her diagnosis is worth separating from the statistics, because it is the sharper point: people do not use loyalty because they do not understand how it works. She can plan a family holiday to Bali paying only the tax, because she knows which card to accumulate on and how to redeem it. That is industry knowledge. A consumer should not need it, and the fact that they currently do is the actual product gap.

Today

Five programs, five logins

  • Each program verifies her separately, at its own cost.
  • Each balance is visible only inside its own app.
  • Nothing is spendable where she actually shops.
  • Expiry dates arrive silently.
  • Knowing how to extract value is a specialist skill.

With Merit ID

Enter your credentials once in your life

  • Verified once, reused by every connected partner.
  • Every connected balance visible in one place.
  • Value spendable at a checkout that accepts points and cash together.
  • The system knows what is expiring and can act on it.
  • The app coaches the user instead of displaying balances.

04The architecture rule

One rule, stated as a directive on 6 August, that decides most future design arguments before they start.

Everything links to Merit ID. Nothing gets its own stack.

When a new project arrives, whether it is Nusuk, NCNP, SAIB or a client marketplace, it attaches to the identity layer rather than receiving a parallel build. The reason is not tidiness. A bespoke platform per client does not compound: ten clients means ten stacks and ten migrations. One identity layer means the tenth client is cheaper than the first and makes the network denser for everyone already on it.

The rule applied, in the case that prompted it

SAIB asked for their own marketplace. The answer is a branded link into the same Merit ID marketplace, not a second one. Duplicating it means a migration later and an internal fight to go with it. This was decided explicitly in the 6 August session.

What this buys, concretely

StakeholderPain todayWhat Merit ID changes
ConsumersSeven to ten cards, under three used. Points expire unseen.One passport. Biometric login in about three seconds instead of thirty. Value usable across every connected program.
BanksRepeated KYC per channel, high account-recovery overhead.KYC done once and reused. New revenue when their points get spent on Merit.
TelcosHuge base, almost no loyalty liquidity.Signed handoff onboards the base fast. Points become spendable across programs.
AirlinesMiles trapped in one program.Cross-issuer redemption against a single identity.
Merchants15 to 20 percent of checkout lost to login friction.One-tap verified checkout. mTrust cuts fraud without adding steps.
GovernmentNeeds high-assurance identity for national programs.Federated identity through Nafath, for cases like Hajj and Umrah.
MeritOne-off platforms per client do not compound.A spine every product plugs into. Captures spread, breakage and float on cross-issuer settlement.

05How an issuer connects

This journey is already built and working. It is the primitive the whole network is made of, so it is worth knowing in detail.

Permission, then token, then live balance

Four steps. After the first three, every later transaction is frictionless, because Merit holds a token rather than asking again.

STEP 1 Issuer authorises The points owner agrees to expose balances to Merit. STEP 2 User authenticates Usually a one-time password on the issuer's own channel. STEP 3 Merit holds a token The consent becomes durable. No repeat permission needed. STEP 4 Live balance reads Spending re-authenticates, reading does not. ONE-TIME COST PERMANENT BENEFIT
The asymmetry is the whole point. Steps one and two cost effort once. Steps three and four keep paying out for as long as the member stays.
Why this is easier than it sounds

Merit already holds contracts with many of these partners from the B2B side of the business. In several cases the remaining work is asking an existing partner to connect, not selling a stranger on the idea. Airlines were deliberately left until later as the hardest counterparties to start with.

06Where the network stands

Density is the asset. Julie is explicit that she will accept weak commercial terms to get a connection in place, because a connection is worth more than the margin on it.

Issuer connection status

As stated in the 6 August session. Status is qualitative, so every row carries a label and a pill rather than relying on colour alone.

IssuerTypeStateDetail
PeopplMerit's own pointsLIVE IN APPThe only issuer a user can actually see today. Managed by Tamer.
BSFBankCONNECTEDConnection established.
Al RajhiBankCONNECTEDConnection established.
ANBBankCONNECTEDConnection established.
STC QitafTelcoALMOST DONEThe signed-handoff pattern the rest of the network reuses.
SAIBBank · JV partnerJV FINAL STAGESWants to invest, not only integrate. See section 08.
AirlinesAirlineDEFERREDDeliberately deprioritised as the hardest counterparties to open with.
Connected means a technical connection exists, not that a consumer can see it in the app. Only Peoppl is visible in the product today, which is the single biggest gap between this page and reality.
The wedge

Jahez, then everyone

No merchant refuses Jahez. As its checkout fills up with loyalty options, Merit ID becomes the obvious way to simplify it, and the rest of the network follows the traffic.

The unlock

Enter as public sector

Approaching an issuer as a Merit B2C product invites a negotiation. Approaching under a national initiative such as NCNP or Nusuk does not. It is very hard for a merchant to refuse a public-sector programme.

The trade

Terms are secondary

Accept a weak commercial deal to get connected. Per-deal margin is recoverable later; a competitor getting there first is not.

07The checkout agent

Everything above is infrastructure. This is the part a consumer feels, and it is the reason the identity layer has to exist first. Julie calls it the ultimate vision.

One checkout, five benefits the consumer did not know about

The agent finds value scattered across programs, coupons, entitlements and memberships, and applies all of it in one pass. Amounts are illustrative; the benefit types are exactly those described in the session.

BASKET Cart total SAR 400.00 WHAT THE AGENT FINDS 200 unused points on an airline programme From a trip taken once. They were going to expire. − SAR 20.00 380.00 A coupon found on the open internet Agentic search, outside Merit's own data entirely. − SAR 25.00 355.00 A birthday discount never claimed An entitlement she already had and forgot. − SAR 30.00 325.00 Saudi Tennis Federation membership, 5 percent Membership as a first-class object on the identity. − SAR 16.25 308.75 You pay Saved SAR 91.25, about 23 percent, with no research and no apps opened. SAR 308.75
Illustrative. The four benefit types and the tennis federation example come from the 6 August session; the cart value and discount amounts are invented to make the arithmetic legible and should not be quoted as targets.

The consumer did not know four of those five benefits existed. That is the product in one sentence, and it is only possible because a single identity can see across programs the consumer experiences as separate companies.

Positioning

Between a wallet and a marketplace

Julie's framing: somewhere between an Apple Wallet, where memberships and cards live, and a marketplace, where value gets spent. The agent is what connects the two halves.

Behaviour

It should coach, not display

A balance screen puts the work back on the consumer, which is exactly the failure described in section 03. The app should tell you what to do, not show you numbers and wish you luck.

Scope honesty

No build has been sized for this yet. The three-month figure discussed in the session came from external contacts describing what they want to see, which is a signal about timing pressure.

08Beyond points

Why a bank wants to invest in this rather than simply integrate with it.

Embedded finance

Lending against aggregated value

If Merit ID knows a member's points across every program are worth ten thousand dollars, a bank can advance against that with no credit application. This is precisely why SAIB wants equity rather than a supplier contract.

Tokenisation

Liquidity for loyalty liabilities

Points sit on an issuer's balance sheet as a liability. With a transparent ledger, Merit can advance liquidity against them and take the redemption risk, which turns loyalty into a financial product rather than a marketing cost.

Data

mTrust as a product

The 1 to 100 trust score exists for Merit's own risk decisions, but it sells standalone to issuers and financial institutions as a risk-signal API. General availability is targeted for October 2026.

Membership, the capability nobody expected to be reusable

The premium membership shaped for Riyadah was originally going to be a standalone microsite. Julie's direction was that it should not be. Membership is a layer of status, entitlements and a digital credential sitting on top of an identity, and Merit ID already owns the identity. So Membership became a native Merit ID feature: tiers, a digital card in Apple and Google Wallet, and a benefits engine that any program can configure. Riyadah is the first tenant, not the only one. It is also what makes the tennis federation discount in section 07 mechanically possible.

09Off-chain to on-chain

Two axes advance separately: how identity is proved, and how a partner connects. Each phase is useful on its own, which is what makes the sequence safe.

Three phases

Phase 3 is the one that changes the character of the thing, and it is a phase Merit can schedule on its own engineering timeline.

NOW TO Q4 2026 2027 Phase 0 · Internal Merit's own roughly 100 staff become the first ID holders. IDENTITY: A1, MERIT-MANAGED Proves the concept without waiting on the B2C launch. Phase 1–2 · Alliance External issuers join by signed handoff and prepaid settlement. CONNECTION: B2 API Onboards in days. Point Exchange runs off-chain. Phase 3 · On-chain Verifiable credential anchored on Avalanche mainnet. IDENTITY: A2, CRYPTOGRAPHIC Partners verify without calling Merit at all.
Removing per-transaction Merit permission is what turns a platform into a network. It is an engineering and legal-opinion step, not a step that waits on a regulator's approval.
Why this is not waiting on a regulator

Merit operates as a Technology Service Provider, not a Virtual Asset Service Provider, and that position is held by design rather than by permission. $MERIT is a closed-loop utility token: it cannot be withdrawn to an external wallet, cannot be traded on a public exchange, and can only be spent inside the Merit merchant network. Merit's interface exposes no fiat off-ramp, so a user who wants fiat conversion is handed to a licensed VASP partner and the exchange happens on that partner's books. The legal precedent is airline miles and Starbucks Stars: real value, not money transmission, because it is restricted to a defined ecosystem.

That is why the constraint below is a hard one. The token must be transfer-restricted at the token level, by allowlist or by being non-transferable, because a freely transferable token could reach a public exchange and form a de-facto off-ramp with no involvement from Merit, which is what would put the classification back in play. Closed-loop has to be engineered in, not assumed from intent. Mainnet is also public, so the mapping from Merit ID to wallet address is held off-chain, encrypted, and must not be inferable on-chain.

10How it earns

Infrastructure pricing on top, network economics underneath. The second one is the reason to build it.

Merit ID sells to partners on verification cost avoided and conversion recovered. The pricing principle is deliberate: set the per-identity fee below what the partner already spends re-verifying and re-acquiring that user, so adopting Merit ID reads as a saving rather than a new line item.

Indicative price per active Merit ID, per month

Volume bands. One measure on one scale, so one hue darkening with volume.

$0.40 $0.25 $0.15 StarterTO 10K Growth10K–100K Scale100K–1M ENTERPRISE, ABOVE 1M ACTIVE IDS, IS PRICED ON APPLICATION
Indicative and not yet validated with the commercial team. Auth0's published per-MAU CIAM pricing is the external anchor these bands were set against.
~85% GM

Identity, verification, mTrust

Behaves like pure SaaS. Cost of goods is auth infrastructure, scoring compute and observability.

55–65% GM

Issuer integration fees

Lower, because onboarding services and data mapping are bundled in. Productising the onboarding lifts it.

Compounds

Cross-issuer spread and FX

High margin, and it grows with network density rather than with seat count. This is the only line that gets structurally better the longer the network runs.

The distinction in that third card is the one that matters over a five-year horizon. Per-seat revenue scales linearly with customers. Settlement spread scales with the connections between customers, which is a different and much steeper curve.

11Why now

The window is open. Nothing about it suggests it stays open long.

Competition

Someone else is building this

Sanabil is working on something in the same space. Merit's advantage is Jahez, and that advantage is fresh rather than permanent.

Exposure

The vision is already outside the building

It has to be discussed for investment reasons, which means the idea is in the open while it is unbuilt. An idea described but not shipped is one somebody else can ship.

Demand

The pull is specific

Contacts across Visa, Google Pay and Apple Pay in the US described this as the next thing they want to see. That is who is applying the timing pressure.

The conclusion drawn on 6 August

Stop letting each new project pull the team off Merit ID, and make progress visible fast. Once a team is dedicated to it, ship something new every month. The named weakness to avoid is Merit's habit of building things and then not enhancing them, which is what turns a platform into a collection of finished projects nobody maintains.

12Where we actually are

Everything above is the destination. This is the starting position, stated plainly, because a vision that overstates the present tense stops being useful the first time somebody checks.

CapabilityStateDetail
Identity system of recordLIVEOff-chain. Auth, KYC tiers, sessions and security all built.
Merit ID appLIVE, UNTESTEDIn the KSA and UAE App Stores as of last week. Deliberately not promoted, still in final testing.
Issuer connection journeyBUILTPermission, OTP, token, live balance reads. Working end to end.
Connected issuers visible in appONEPeoppl only. The multi-issuer experience is not yet visible to any user.
Bulk identity creationBUILTProven on the Gift Global migration, 1,341 users.
In-app marketplaceINCOMPLETECannot yet replace Gift Global, which is what gates decommissioning it.
mTrust ScoreIN BUILDGeneral availability targeted October 2026.
Membership featureBRD DRAFTv0.1, awaiting decisions on tiers, pricing and first program.
AI agent at checkoutCONCEPTNo build sized yet. The three-month figure is an external expectation.
On-chain credentialCONCEPT2027. Design and regulatory analysis are done; closed-loop keeps it outside VASP scope.
Two things to fix before this is shown widely

Gift Global is a known security exposure and stays live until the Merit ID marketplace can replace it. And the app is region-locked to the KSA and UAE stores, so colleagues elsewhere, including the CPO in France, cannot install it from their own App Store at all. Neither is fatal. Both are embarrassing to discover in front of a partner.

13Glossary

Terms that appear across the Merit ID specs and mean something specific.

Merit ID
A unique handle, for example @brian, mapped to a verified phone, email and KYC status. The identity itself, not the app that surfaces it.
Member vs User
A Member is a retail consumer holding a Merit ID. A User is a corporate or merchant admin who signs into dashboards through normal corporate auth. Only Members have a Merit ID.
mTrust Score
A 1 to 100 fraud and transaction-integrity score computed from in-ecosystem behaviour. Drives KYC tier limits and velocity caps, and sells standalone as a risk API.
A1 and A2
Identity models. A1 is Merit-managed and off-chain: partners verify by calling Merit, so Merit is the gatekeeper. A2 is an on-chain verifiable credential: partners verify cryptographically without Merit in the loop.
B1 and B2
Partner connection models. B2 is a B2B API with a signed handoff and a prepaid deposit, onboarding in days. B1 is a strategic anchor partner interacting natively on mainnet.
Signed handoff
The proven STC Qitaf pattern. The issuer sends one identifier such as a phone number, Merit enriches the record once, and every later transaction is frictionless. It is effectively a primitive version of the A2 credential.
Nafath
The Saudi national identity API. An identity source rather than a points issuer, used where a government level of assurance is required, such as Hajj and Umrah programs.
Transfer-restricted token
A token that can only move between allowlisted addresses, or cannot move at all. The mechanism that keeps the on-chain phase closed-loop and outside virtual-asset regulation.
Point Exchange
The any-to-any point conversion engine, with a rate table built from a peg plus a Merit spread. The component that makes cross-issuer redemption possible.