Merit · Product · Internal Explainer
The B2C Super App aggregates a consumer's points into one wallet. Merit ID is the layer underneath it that makes that possible, and it does not stop at points. One verified identity that carries value, status and trust across every Merit product and every partner who plugs in. This page starts at the one-minute version and ends at an honest status.
“Anytime we have a new project, we push everything to Merit ID. At the end of the day, link everything to the Merit ID.”
Julie Barbier, Chief Product Officer · ELM session, 6 August 2026If you only read one section, read this one.
A Gulf consumer holds seven to ten loyalty cards and actively uses fewer than three. Every platform makes them sign up again and prove who they are again. In KSA alone an estimated SAR 2.4B of points expire unused every year, and identity friction costs e-commerce merchants an estimated 15 to 20 percent of checkout conversion. Both problems have the same root: identity does not travel, so value cannot travel either.
Merit ID is the layer that makes identity travel. One bank-grade, KYC-verified identity, a loyalty passport, that a consumer carries across every Merit storefront, app and partner program. The consumer verifies once. The partner never re-verifies. Every Merit product plugs into the same spine instead of rebuilding it.
The B2C Super App is the most visible thing standing on Merit ID, but it is not the point of it. Merit ID is what stops Merit building a bespoke platform per client and starts it building a network where each new partner makes the next one easier to sign.
The whole thing in one picture
Issuers and identity sources on the left, verified once. Merit products on the right, none of which build identity themselves. Merit ID is the only thing in the middle.
Off-chain. Auth, KYC tiers, sessions and security are built and running. Bulk creation is proven on the Gift Global migration, 1,341 users.
Peoppl only. The connection journey works end to end, but a user cannot yet see the multi-issuer experience this page describes.
Stated as a directive on 6 August, not a preference. Nusuk, NCNP, SAIB and every future program attach to Merit ID rather than getting their own stack.
Five roles. The one that separates Merit ID from an authentication product is the government identity source, and the one that separates it from a loyalty engine is the issuer.
Merit ID separates the Member, a retail consumer who holds a Merit ID, from the User, a merchant or corporate admin who signs into a dashboard through normal corporate auth. Only Members have a Merit ID. If you are reading a spec and the two seem interchangeable, they are not.
The market numbers say value is being destroyed. Julie's account of her own wallet says why.
Loyalty points expiring unused in KSA alone. The value is real, it belongs to the consumer, and it is unreachable.
The average Gulf consumer. Every unused card is a program that paid to acquire someone who never came back.
Of e-commerce checkout conversion, lost to identity and login friction alone, before anyone considers price.
Julie described her own position as a consumer: a mother of three shopping at Carrefour, a Merit employee with her own points, an SAIB customer, an Al Rajhi customer, Al Fursan Gold, and an Optimoji member. Her question was not rhetorical. What does all of that actually give her? She cannot tell, because every piece of it is somewhere else.
Her diagnosis is worth separating from the statistics, because it is the sharper point: people do not use loyalty because they do not understand how it works. She can plan a family holiday to Bali paying only the tax, because she knows which card to accumulate on and how to redeem it. That is industry knowledge. A consumer should not need it, and the fact that they currently do is the actual product gap.
Five programs, five logins
Enter your credentials once in your life
One rule, stated as a directive on 6 August, that decides most future design arguments before they start.
Everything links to Merit ID. Nothing gets its own stack.
When a new project arrives, whether it is Nusuk, NCNP, SAIB or a client marketplace, it attaches to the identity layer rather than receiving a parallel build. The reason is not tidiness. A bespoke platform per client does not compound: ten clients means ten stacks and ten migrations. One identity layer means the tenth client is cheaper than the first and makes the network denser for everyone already on it.
SAIB asked for their own marketplace. The answer is a branded link into the same Merit ID marketplace, not a second one. Duplicating it means a migration later and an internal fight to go with it. This was decided explicitly in the 6 August session.
| Stakeholder | Pain today | What Merit ID changes |
|---|---|---|
| Consumers | Seven to ten cards, under three used. Points expire unseen. | One passport. Biometric login in about three seconds instead of thirty. Value usable across every connected program. |
| Banks | Repeated KYC per channel, high account-recovery overhead. | KYC done once and reused. New revenue when their points get spent on Merit. |
| Telcos | Huge base, almost no loyalty liquidity. | Signed handoff onboards the base fast. Points become spendable across programs. |
| Airlines | Miles trapped in one program. | Cross-issuer redemption against a single identity. |
| Merchants | 15 to 20 percent of checkout lost to login friction. | One-tap verified checkout. mTrust cuts fraud without adding steps. |
| Government | Needs high-assurance identity for national programs. | Federated identity through Nafath, for cases like Hajj and Umrah. |
| Merit | One-off platforms per client do not compound. | A spine every product plugs into. Captures spread, breakage and float on cross-issuer settlement. |
This journey is already built and working. It is the primitive the whole network is made of, so it is worth knowing in detail.
Permission, then token, then live balance
Four steps. After the first three, every later transaction is frictionless, because Merit holds a token rather than asking again.
Merit already holds contracts with many of these partners from the B2B side of the business. In several cases the remaining work is asking an existing partner to connect, not selling a stranger on the idea. Airlines were deliberately left until later as the hardest counterparties to start with.
Density is the asset. Julie is explicit that she will accept weak commercial terms to get a connection in place, because a connection is worth more than the margin on it.
Issuer connection status
As stated in the 6 August session. Status is qualitative, so every row carries a label and a pill rather than relying on colour alone.
| Issuer | Type | State | Detail |
|---|---|---|---|
| Peoppl | Merit's own points | LIVE IN APP | The only issuer a user can actually see today. Managed by Tamer. |
| BSF | Bank | CONNECTED | Connection established. |
| Al Rajhi | Bank | CONNECTED | Connection established. |
| ANB | Bank | CONNECTED | Connection established. |
| STC Qitaf | Telco | ALMOST DONE | The signed-handoff pattern the rest of the network reuses. |
| SAIB | Bank · JV partner | JV FINAL STAGES | Wants to invest, not only integrate. See section 08. |
| Airlines | Airline | DEFERRED | Deliberately deprioritised as the hardest counterparties to open with. |
No merchant refuses Jahez. As its checkout fills up with loyalty options, Merit ID becomes the obvious way to simplify it, and the rest of the network follows the traffic.
Approaching an issuer as a Merit B2C product invites a negotiation. Approaching under a national initiative such as NCNP or Nusuk does not. It is very hard for a merchant to refuse a public-sector programme.
Accept a weak commercial deal to get connected. Per-deal margin is recoverable later; a competitor getting there first is not.
Everything above is infrastructure. This is the part a consumer feels, and it is the reason the identity layer has to exist first. Julie calls it the ultimate vision.
One checkout, five benefits the consumer did not know about
The agent finds value scattered across programs, coupons, entitlements and memberships, and applies all of it in one pass. Amounts are illustrative; the benefit types are exactly those described in the session.
The consumer did not know four of those five benefits existed. That is the product in one sentence, and it is only possible because a single identity can see across programs the consumer experiences as separate companies.
Julie's framing: somewhere between an Apple Wallet, where memberships and cards live, and a marketplace, where value gets spent. The agent is what connects the two halves.
A balance screen puts the work back on the consumer, which is exactly the failure described in section 03. The app should tell you what to do, not show you numbers and wish you luck.
No build has been sized for this yet. The three-month figure discussed in the session came from external contacts describing what they want to see, which is a signal about timing pressure.
Why a bank wants to invest in this rather than simply integrate with it.
If Merit ID knows a member's points across every program are worth ten thousand dollars, a bank can advance against that with no credit application. This is precisely why SAIB wants equity rather than a supplier contract.
Points sit on an issuer's balance sheet as a liability. With a transparent ledger, Merit can advance liquidity against them and take the redemption risk, which turns loyalty into a financial product rather than a marketing cost.
The 1 to 100 trust score exists for Merit's own risk decisions, but it sells standalone to issuers and financial institutions as a risk-signal API. General availability is targeted for October 2026.
The premium membership shaped for Riyadah was originally going to be a standalone microsite. Julie's direction was that it should not be. Membership is a layer of status, entitlements and a digital credential sitting on top of an identity, and Merit ID already owns the identity. So Membership became a native Merit ID feature: tiers, a digital card in Apple and Google Wallet, and a benefits engine that any program can configure. Riyadah is the first tenant, not the only one. It is also what makes the tennis federation discount in section 07 mechanically possible.
Two axes advance separately: how identity is proved, and how a partner connects. Each phase is useful on its own, which is what makes the sequence safe.
Three phases
Phase 3 is the one that changes the character of the thing, and it is a phase Merit can schedule on its own engineering timeline.
Merit operates as a Technology Service Provider, not a Virtual Asset Service Provider, and that position is held by design rather than by permission. $MERIT is a closed-loop utility token: it cannot be withdrawn to an external wallet, cannot be traded on a public exchange, and can only be spent inside the Merit merchant network. Merit's interface exposes no fiat off-ramp, so a user who wants fiat conversion is handed to a licensed VASP partner and the exchange happens on that partner's books. The legal precedent is airline miles and Starbucks Stars: real value, not money transmission, because it is restricted to a defined ecosystem.
That is why the constraint below is a hard one. The token must be transfer-restricted at the token level, by allowlist or by being non-transferable, because a freely transferable token could reach a public exchange and form a de-facto off-ramp with no involvement from Merit, which is what would put the classification back in play. Closed-loop has to be engineered in, not assumed from intent. Mainnet is also public, so the mapping from Merit ID to wallet address is held off-chain, encrypted, and must not be inferable on-chain.
Infrastructure pricing on top, network economics underneath. The second one is the reason to build it.
Merit ID sells to partners on verification cost avoided and conversion recovered. The pricing principle is deliberate: set the per-identity fee below what the partner already spends re-verifying and re-acquiring that user, so adopting Merit ID reads as a saving rather than a new line item.
Indicative price per active Merit ID, per month
Volume bands. One measure on one scale, so one hue darkening with volume.
Behaves like pure SaaS. Cost of goods is auth infrastructure, scoring compute and observability.
Lower, because onboarding services and data mapping are bundled in. Productising the onboarding lifts it.
High margin, and it grows with network density rather than with seat count. This is the only line that gets structurally better the longer the network runs.
The distinction in that third card is the one that matters over a five-year horizon. Per-seat revenue scales linearly with customers. Settlement spread scales with the connections between customers, which is a different and much steeper curve.
The window is open. Nothing about it suggests it stays open long.
Sanabil is working on something in the same space. Merit's advantage is Jahez, and that advantage is fresh rather than permanent.
It has to be discussed for investment reasons, which means the idea is in the open while it is unbuilt. An idea described but not shipped is one somebody else can ship.
Contacts across Visa, Google Pay and Apple Pay in the US described this as the next thing they want to see. That is who is applying the timing pressure.
Stop letting each new project pull the team off Merit ID, and make progress visible fast. Once a team is dedicated to it, ship something new every month. The named weakness to avoid is Merit's habit of building things and then not enhancing them, which is what turns a platform into a collection of finished projects nobody maintains.
Everything above is the destination. This is the starting position, stated plainly, because a vision that overstates the present tense stops being useful the first time somebody checks.
| Capability | State | Detail |
|---|---|---|
| Identity system of record | LIVE | Off-chain. Auth, KYC tiers, sessions and security all built. |
| Merit ID app | LIVE, UNTESTED | In the KSA and UAE App Stores as of last week. Deliberately not promoted, still in final testing. |
| Issuer connection journey | BUILT | Permission, OTP, token, live balance reads. Working end to end. |
| Connected issuers visible in app | ONE | Peoppl only. The multi-issuer experience is not yet visible to any user. |
| Bulk identity creation | BUILT | Proven on the Gift Global migration, 1,341 users. |
| In-app marketplace | INCOMPLETE | Cannot yet replace Gift Global, which is what gates decommissioning it. |
| mTrust Score | IN BUILD | General availability targeted October 2026. |
| Membership feature | BRD DRAFT | v0.1, awaiting decisions on tiers, pricing and first program. |
| AI agent at checkout | CONCEPT | No build sized yet. The three-month figure is an external expectation. |
| On-chain credential | CONCEPT | 2027. Design and regulatory analysis are done; closed-loop keeps it outside VASP scope. |
Gift Global is a known security exposure and stays live until the Merit ID marketplace can replace it. And the app is region-locked to the KSA and UAE stores, so colleagues elsewhere, including the CPO in France, cannot install it from their own App Store at all. Neither is fatal. Both are embarrassing to discover in front of a partner.
Terms that appear across the Merit ID specs and mean something specific.
@brian, mapped to a verified phone, email and KYC
status. The identity itself, not the app that surfaces it.