Preview: wellknown.id is in development and isn’t live yet

Uses · All your devices

All your devices, one you.

Your passkey, a recovery code or kivi unlocks the same wellknown.id on any of your devices, so every site knows you as the same person on each. Lose a device, and you’re back in with another.

How it works

One keyring, on every device.

  • Your passkey opens your keyring on any device: every persona, and their records. Syncing the passkey (Google, Apple, a password manager) is how a new device gets back in. A recovery code brings back one persona.
  • On a device without your passkey, sign in with kivi on your phone, or use the browser’s own “use a phone” passkey sign-in.

Bonds

Bond your devices, end to end.

  • Scan a code, and two devices bond: phone to phone, browser to phone, browser to browser. What passes between them is end-to-end encrypted, and the relay that passes it along keeps no record.
  • You say what a bond is for first: your own device, a limited one (a work phone), or someone else’s. Both screens show it beside six digits, before either side confirms.
  • Your own devices share your keyring. A limited device holds only the personas you choose for it. Someone else’s gets none.
  • Bonding one of yours joins it to all of them, and removing one removes it from all of them. A removed device keeps what it had already seen, and kivi tells you so.

Personas meeting

When both devices have personas.

  • A persona that was never used folds in quietly: hidden, not deleted, with 90 days to undo it.
  • Personas used on both sides are named first. Each screen says what bonding will bring before you confirm, and afterwards you can choose between them.
  • The same when a passkey finds a second keyring: the two are merged, and either passkey opens the result. Nothing is deleted silently.

What stays put

Documents and secrets stay where they are.

  • Your passport or ID card is read on your phone and stays there.
  • Secrets such as API keys stay on the device that keeps them. Another of your devices can ask for one, and the keeping device asks you first.
  • An unlock brings back your personas and their records, not documents, secrets or bonds. kivi keeps itself out of your phone’s backups.
  • Before bonding, kivi checks that wellknown.id is serving the pages in its public release log, and won’t bond if it isn’t.

What to know

What works today, and what doesn’t yet.

  • Works now: bonding in browsers and on Android and iPhone; groups joined by one bonding; waking a phone with a notification that carries nothing but “a request is waiting”; and your keyring and personas carried over bonds, in kivi on the web.
  • On phones, carrying personas and checking the pages need a new build of kivi, not yet run on a phone.
  • Limits: a device hears requests only while kivi is open on it, or after that wake-up, which kivi on the web can’t have yet.

wellknown.id is in development. This page says what works now, and nothing more.