Preview: wellknown.id is in development and isn’t live yet

Uses · Rules you can read

Rules you can read, not fine print.

A site says what it requires for signing in, in karu, a small policy language designed to be read by people and not just machines. It publishes the rules with its wellknown.id config, for anyone to read.

An example

Two rules.

deny not_p256 if
  principal.key_type != "P-256";
deny no_popin if
  context.mode == "popin" and
  resource.domain like "*.bank.example";

The first asks for a P-256 key. The second keeps sign-ins on the bank’s own pages out of a frame. Each rule has a name, so when one says no, the site is told which.

When it’s checked

Every sign-in, before the site gets anything.

  • After you prove your key, before a code is issued. wellknown.id checks the site’s rules every time, on every way of signing in: the browser’s dialog, the pop-up, the redirect, and kivi on your phone.
  • A site’s rules can only say no. wellknown.id’s own rules, also in karu, allow a plain sign-in and are checked first. A site’s rules narrow that, and any rule that says no wins.
  • The site is told which rule said no, so it can say so. Signing in through the browser’s dialog, wellknown.id’s window tells you too.
  • Bring rules you already have. karu can read Cedar policies and convert them to karu, so an organisation needn’t start again.

What to know

What works today, and what doesn’t yet.

  • Works now: sites’ sign-in rules, and wellknown.id’s own, both in karu, checked at every sign-in that wellknown.id issues.
  • A site that takes your proof itself (where its file allows it) checks its own rules: wellknown.id isn’t in the way to check them.
  • Still to come: rules about what you share, such as being over 18, and rules you write yourself, checked on your device.

wellknown.id is in development. This page says what works now, and nothing more.