When using Incognito Actions, it’s important to always verify the proof received from IDKit. This proof is a claim that the user has been verified by World ID, and verifying that proof with our API or smart contracts is the only way to ensure that the claim is true.
If you specify a signal as an input to IDKit, ensure you include the same signal when verifying the proof with our API or smart contracts. Otherwise, the proof will not verify.