City of Hats and Threema document service-generated identities that can be used without linking either identifier.
Which messengers require a phone number or email?
A reproducible August 2026 audit of the account identifiers documented by nine messaging services. The study separates the identifier used to create an account from the information a user can later hide from contacts.
Version 1.0 · 9 services · 8 verified classifications · 1 unscoredThe short finding
What the documentation shows
Signal, WhatsApp, and Telegram document a phone-linked account root even when optional usernames can hide the number from new contacts.
Messenger can use an email-confirmed Meta account; Wire documents email-based team accounts.
LINE documents phone verification in five Asian markets and Apple or Google account creation elsewhere.
Methodology
This is a documentation audit, not a source-code audit and not a security ranking. Each classification answers one narrow question: what durable identifier does the service say a person needs when creating or maintaining an account?
We used vendor help centers, technical papers, or official product announcements. Search snippets and third-party summaries were not accepted as evidence.
A username that hides a phone number from a new contact does not erase the phone number used to register or recover the underlying account.
Regional rules, staged rollouts, enterprise-only flows, and inaccessible documentation are labeled instead of being forced into yes-or-no cells.
Products change. Every row includes its review date and source so another researcher can reproduce or challenge the classification.
Identity requirement dataset
“None” means the cited documentation allows use without a phone number or email. It does not mean the service collects no metadata or that the user is anonymous in every threat model.
| Service | Documented account root | Phone required | Email required | Contact-facing alias | Confidence | Official sources |
|---|---|---|---|---|---|---|
| City of Hats | Service-generated Hat identity | No | No | Hat code or Phrase ID | First-party claim | Security Evidence CenterA phone number and email are not required to create a Hat. This is a City of Hats first-party product claim, not an independent audit finding. |
| Signal | Existing mobile phone number | Yes | No | Optional username | Verified | Signal registration requirementsSignal says an existing phone number is required. Its optional username and privacy settings can prevent new contacts from seeing or finding that number. |
| Phone-number-based account | Yes | No | Username rollout in progress | Verified with rollout caveat | Meta username announcementMeta says usernames will let new contacts avoid seeing a phone number. We treat that as contact privacy, not removal of the underlying phone-linked account. | |
| Telegram | Mobile phone number | Yes | No | Optional username | Verified | Telegram FAQTelegram states accounts can only be connected to a mobile number and warns users to retain control of it. |
| Facebook Messenger | Meta or Facebook account | No | Yes, if phone is not used | Profile or username | Verified | Messenger Help CenterFacebook account creation accepts an email address or mobile number, so a phone number is not strictly required. The account remains tied to a stable Meta identity. |
| LINE | Phone number or Apple/Google account by region | Regional | Third-party account | LINE profile and ID | Verified with regional caveat | LINE account creationLINE documents phone verification in Hong Kong, Japan, Korea, Taiwan, and Thailand; users in other countries create an account with Apple or Google. |
| Threema | Random Threema ID | No | No | Threema ID | Verified | Threema cryptography whitepaperThreema documents phone-number and email linking as optional. Its generated ID remains the primary identifier. |
| Wire | Email-based team account | No | Yes | Wire profile | Verified for team accounts | Wire account supportThe accessible current documentation describes team creation and membership using a verified email address. This row does not generalize beyond that documented flow. |
| Not classified | Not scored | Not scored | WeChat ID | Insufficient accessible first-party evidence | WeChat official siteWe could not reliably retrieve a current first-party signup requirement document during this audit, so this row is intentionally unscored. |
What this does—and does not—mean
- A registration identifier is one part of a threat model. It can affect discoverability, account recovery, cross-context correlation, and exposure to SIM-swap or email-account compromise.
- It does not determine message confidentiality by itself. A phone-based service can still implement strong end-to-end encryption, and a pseudonymous account can still be exposed by an unlocked device, recipient behavior, network metadata, or operational mistakes.
- The most useful question is not “Which app wins?” It is “Which identifier, recovery path, device, recipient, and metadata risks matter in this situation?”
How City of Hats handles identity separation
City of Hats uses service-generated Hats rather than a carrier number or email address as the communication identity. Phrase ID can make a Hat easier to share, and Disposable Hats can limit how long a context remains linkable. These controls reduce identifier coupling; they do not prevent device compromise, recipient disclosure, traffic observation, or physical coercion.
Download and reproduce the audit
The CSV is convenient for analysis and the JSON preserves notes, source URLs, confidence labels, and classification codes. Both are published under CC BY 4.0 with attribution to City of Hats and a link to this methodology page.
Dataset license: Creative Commons Attribution 4.0 · Version 1.0
Limitations
- This study evaluates public documentation, not source code, server behavior, privacy-policy compliance, or cryptographic implementation.
- Signup flows can vary by country, device, account type, age, or staged feature rollout.
- City of Hats is included and funded this research. Its row is clearly marked as a first-party claim.
- The counts exclude WeChat because its current first-party signup documentation was not reliably accessible during the audit.
- Corrections with a first-party source are welcome through the contact page. Material changes will appear in the changelog.