Next week the 2026 FIFA World Cup opens across Mexico, the United States, and Canada — and alongside the football, it sets up one of the largest age- and identity-verification tests the industry has run in years. The reason is the surge in online betting.
A recent Jumio study of 8,003 adults across four countries found that Mexico leads online-betting intent for the tournament at 43% — the highest of any market surveyed — with many people expected to place a bet for the first time. At the same time, 63% worry that minors will reach these platforms, and 74% believe that verifying age is the responsibility of the platforms and the technology providers behind them.
Millions of people will need to prove they are old enough to play, in seconds, at exactly the moment demand spikes — and this edition is about how that proof can work at that scale without creating new harm along the way.
The shape of the problem
A betting platform during the World Cup faces three things at once: a flood of new users, a legal duty to confirm each one is of legal age and eligible, and a window of a few seconds before an impatient fan abandons the process. The stakes on the age question are real — Jumio’s research shows betting has become part of how nearly half of fans enjoy the tournament, and most adults expect platforms and their technology to keep minors out. Getting verification right at this volume, under this time pressure, is the actual contest happening behind the matches.
What verification usually costs today
The common approach asks each person to upload a full identity document — a passport or national ID — which the platform then stores to satisfy its records. That single design choice carries three costs. It adds friction precisely when attention is thin, so legitimate users drop off. It does little to stop a minor presenting a borrowed document. And it leaves the platform holding a growing archive of passports, which becomes exactly the kind of database that fraud and breaches target. The platform ends up responsible for protecting data it never actually needed.
Confirming age without keeping the document
There is a way to answer the only question that matters — is this person old enough and eligible — without the platform ever holding the document behind it. A verifiable credential, issued once by a trusted source such as a government or a bank, lives in the person’s digital wallet on their own device. With selective disclosure (SD-JWT), the holder presents proof of the single relevant claim — that they meet the legal-age and eligibility rule — and the platform verifies the issuer’s signature on that one claim through an API like SovraID without ever seeing the rest. The platform stores a proof that the check passed, rather than a copy of a passport. The direction the standards are heading — zero-knowledge proofs — narrows it further still: a person can prove they are over the legal age without revealing even their date of birth. The verification happens in seconds, and the sensitive data never leaves the device. (We walked through the full stack that makes this work in last month’s edition, How Sovra is built.)
Trust once. Use everywhere.
For Latin America, hosting an event of this size is a chance to show that serious digital identity can keep pace with a global moment. The technology is ready; what remains is the choice to use it well.
Want to go deeper?
SovraWallet — the credential a citizen carries · SovraID — the API of digital trust · SovraChain — the verifiable trust anchor
Previous editions: How Sovra is built · Zero-Knowledge Proofs Explained With Your Driver’s License · What Happens After a Verifiable Credential Is Issued?
The research: Jumio 2026 Online Identity Study · Biometric Update analysis · The World Cup’s Hidden Scoreboard (infographic)
Standards: W3C Verifiable Credentials 2.0 · SD-JWT (IETF) · ISO/IEC 18013-5 mDL





