Hereby’s pilot starts this winter, and nothing on this site can be used yet. The roadmap has the details.

hereby Founding partners

Hereby for developers

Verify a visit.

Ask a visitor for their visits Planned

It works like a "sign in" button, but for visits. Your app asks a visitor to share their visits, and nothing is shared without their explicit permission. They approve on their own phone, see what's being shared, and can stop any time. Your app gets a private ID that only it uses, and only the places the visitor chose to share, never their raw location.

What you could build

  • Verify a visit: send a proof and get back valid or not valid, the place, the month and the trust level. Use it to show "visited, March 2027" on a review. Planned
  • Ask for permission to read a visitor's visits, for a travel journal or an attendance record. Planned
  • Get a webhook when a visitor presents a proof to your app or revokes access. Planned
  • Test everything with sandbox tags and sample proofs, with no real venue involved. Planned
  • Use an official SDK, JavaScript first, then iOS and Android. Planned
  • Developer-built apps on top of visits, tourism challenges, continuing-education proof. Idea

What a proof says

A proof says someone was here, around then. It doesn't say who. It holds the place, a rounded time window (not the exact second), the trust level, an ID that's different for each place and each app, and Hereby's signature.

In concept

API in design, subject to change. Names, fields and URLs are placeholders. Sample data, for illustration.

POST https://api.hereby.ca/v1/proofs/verify   (design, subject to change)
Authorization: Bearer <your sandbox key>

{ "proof": "<proof presented by the visitor>" }
{
  "valid": true,
  "place": { "id": "plc_sample123", "name": "Sample Taproom" },
  "visit_month": "2027-03",
  "trust_level": 1
}
import { Hereby } from "@hereby/sdk";   // placeholder name

const hereby = new Hereby({ appId: "app_sample", mode: "sandbox" });

const grant = await hereby.requestAccess({
  scopes: ["visits:place", "visits:month"],  // never raw location
});
// The visitor approves on their phone. You get a private per-app ID
// and only the places they chose to share.
{
  "type": "access.revoked",
  "app_visitor_id": "av_sample789",
  "created": "2027-03-14T10:00:00Z"
}

Event types we're designing: proof.presented, access.granted, access.revoked. No payload carries a name, email or location. Only the visit month is public.

Sandbox

Planned · early access. Test tags and sample proofs, with no real visitor data. No charge during early access. We'll publish the terms.

Audit trail

Planned We plan to publish a fingerprint of every proof to a public record, so anyone can check that our record wasn't changed. We haven't chosen which public record yet.

Rules

Planned Sensitive places (clinics, places of worship) are excluded. Our terms will forbid resale and re-identification. Proofs used for reviews are meant to expire after about 90 days, with one review per visit.

What you won't get

A visitor's name or contact details, a list of the places someone has been unless they approved it, or any data from people who didn't tap.

Get early access