Earlier quoted context omitted.
An id card is a bearer token. You can get an anonymous, cryptographically signed, certified legal bearer token confirming your age only , or identity or whatever by a centralized service, be it government or high trust private organizations who need to verify your identity anyway like banks. With some smarts you can probably make such a token yourself so the root bearer token issuer doesn’t have the one you use to br…
Which inevitably can be deanonymized after a simple law change, mandating the required data to be reported.
Perhaps a system like Privacy Pass would be ideal. Where a verifier generates a verified client a number of redeemable signed tokens for a session, but when presented by a client, the site doesn't know who that token was issued to, but they know they authenticated this person and can verify they made the token. Therefore they get access.