Preview: wellknown.id is in development and isn’t live yet

Uses · Sign in

Sign in anywhere, with nothing to create.

Look for “Continue with wellknown.id” on a site. There’s no account to make and no password to set: you prove you hold your key for that site, and the site gets an identifier it will recognise next time.

How it works

One tap, one proof, nothing kept.

  1. The site shows the button. It has published a small file at /.well-known/id saying who it is and where sign-ins may return to. That’s all it needs to do: no registration with us, no client secret.
  2. You prove you hold your key for that site. wellknown.id sends a single-use challenge. Your browser signs it with the key it makes for that site, in a short token that names the site and lasts two minutes. Your passkey opens your keys; the key itself never leaves your device.
  3. wellknown.id checks the proof, and forgets it. It checks the signature in memory, then gives the site a standard OpenID Connect code. It keeps no session, sets no cookie that names you, and logs nothing about who signed in where.
  4. The site gets a verified identifier. Its token says “this is the holder of this key”. The site checks it the usual way, and knows you next time.

Who learns what

An identifier, and nothing more.

  • The site learns a did:key, the public half of the key made for that site, which anyone can check signatures against. Not your name, not your email address, and nothing about your other sites.
  • Sites can’t compare notes. Each site gets a different key, so two sites can’t tell they’ve met the same person unless you tell them.
  • You can be more than one person. Each of your personas has its own key at every site. The sign-in page picks the one you used there before, and asks when you’ve used more than one.
  • wellknown.id learns which site you’re signing in to, for as long as the sign-in takes, and keeps none of it.
  • It’s ordinary OpenID Connect underneath (authorization code with PKCE), so a site can use the libraries it already has.

What to know

What works today, and what doesn’t yet.

  • Works now: signing in through the browser’s own dialog (FedCM, in Chrome and Edge), a pop-up, or a full-page redirect, in Chrome, Edge and Firefox. Your passkey, a recovery code or kivi opens your keys. Safari isn’t tested yet.
  • No passkey in this browser? Sign in with kivi on your phone: it scans the code the sign-in page shows, and signs that one sign-in. Your keys stay on the phone. This works with kivi on the web today; kivi for Android and iPhone needs a new build for it, not yet tried on a phone.
  • Sites may take the proof themselves, if their file says so. Then wellknown.id isn’t sent your key for that sign-in at all.
  • Only sites that have published their file can use it, and there are few of those yet.
  • Still to come: a sister service connecting a persona to accounts you already have, such as Google or LinkedIn (Accounts you already have); and passwords and authenticator codes, kept for you, for sites that don’t take wellknown.id yet.
  • For sites: see the developer notes: one file and a script tag.

wellknown.id is in development. This page says what works now, and nothing more.