Preview: wellknown.id is in development and isn’t live yet

Uses · No passwords

No passwords. Nothing to remember, nothing to leak.

Instead of a password, your browser signs a one-time challenge with your key. There’s nothing to remember, reuse or phish, and no password database to breach, because there are no passwords.

How it works

A signature, used once.

  1. The site asks to sign you in. wellknown.id gives your browser a single-use challenge.
  2. Your browser signs it, with the key it keeps for that site, in a short token that names the site and is good for two minutes, once.
  3. wellknown.id checks the signature against the key’s public half, in memory, and the site gets its answer. Nothing about the sign-in is kept.

Why it’s safer

Nothing worth stealing.

  • A signature works once, for one site, for that moment. Anyone who intercepts it gets nothing they can use.
  • A fake site gets nothing. The challenge is signed for the real site’s name, and the key for another name is a different key.
  • Nothing to reuse. Each site has a key of its own, so a breach at one tells an attacker nothing about another.
  • Nothing to take from wellknown.id either. It holds no passwords, no keys, and no list of who signed in where.

What to know

What works today, and what doesn’t yet.

  • Works now: a fresh proof of your key at every sign-in. There’s no session to ride on: wellknown.id keeps none, and sets no cookie of its own.
  • Your passkey is the way in to your keys, not a password in disguise: your device unlocks it with your fingerprint, face or PIN, and the site never sees it.
  • Still to come: passwords and authenticator codes, kept by kivi, for the sites that still ask for them.

wellknown.id is in development. This page says what works now, and nothing more.