Uses · In the browser
Built into the browser.
Browsers are building sign-in into their own interface, a standard called FedCM. Where it’s available, signing in with wellknown.id starts in the browser’s own trusted dialog, which a page can’t fake.
How it works
The best way each browser has.
- FedCM, where the browser has it (Chrome and Edge). The browser draws the first dialog, which a page can’t imitate or reach into. It shows one account, “wellknown.id”, the same for everyone: wellknown.id doesn’t know who you are, and reads no cookie to find out.
- Then wellknown.id’s own window, every time. It opens your keys, picks the persona you use at that site, and signs. With nothing to ask, it shows the site and the persona for a second, then closes. “Change persona” and “Use my phone” are there if you want them.
- A small pop-up from wellknown.id does the same job where FedCM isn’t available (Firefox), and a full-page redirect is the last resort if pop-ups are blocked.
- The site doesn’t choose. Its button picks the best way the browser supports.
Why it matters
Nothing depends on cookies.
Browsers are closing off the tricks older single sign-on relied on. wellknown.id uses none of them: no third-party cookies, and no cookie of its own that names you. The only cookies it sets belong to a sign-in in progress, and are gone within ten minutes.
The price is that there’s no silent sign-in: every sign-in is a click and a window. That’s what keeping nothing on the server costs.
What to know
What works today, and what doesn’t yet.
- Works now: FedCM in Chrome and Edge, and the pop-up and redirect in Chrome, Edge and Firefox, measured in tests and on wellknown.id itself.
- Not yet tested: Safari, and Chrome on Android.
- Browsers are still changing. Support for FedCM differs between them, and this page follows what we’ve measured, not what’s promised.
wellknown.id is in development. This page says what works now, and nothing more.