How it works
One tap, one proof, nothing kept.
- The site shows the button. It has published a small file at
/.well-known/idsaying who it is and where sign-ins may return to. That’s all it needs to do: no registration with us, no client secret. - You prove you hold your key for that site. wellknown.id sends a single-use challenge. Your browser signs it with the key it makes for that site, in a short token that names the site and lasts two minutes. Your passkey opens your keys; the key itself never leaves your device.
- wellknown.id checks the proof, and forgets it. It checks the signature in memory, then gives the site a standard OpenID Connect code. It keeps no session, sets no cookie that names you, and logs nothing about who signed in where.
- The site gets a verified identifier. Its token says “this is the holder of this key”. The site checks it the usual way, and knows you next time.