What we can see
What wellknown.id can and can’t see.
We built wellknown.id so that our server has nothing about you worth stealing. Here is what that means in practice, where it stops, and what you still trust us with.
Never
What our server never holds.
- Your keys. They’re made on your own device, and used there. We never receive one.
- Your secret, the seed your keys come from. We keep it only locked, in a form we can’t open (below).
- Your personas’ names. “Work” or “Home” lives only on your devices, and inside copies we can’t read.
- Which sites you use. We don’t record where you sign in, or when.
- Your sign-in tokens. We hand each one to the site and keep no copy.
- Cookies about you. No cookie of ours says who you are or where you’ve been.
- Your name, email address, date of birth or password. We never ask for them, so there’s nothing to keep.
- Logs of your visits. Like any website, our server receives your IP address so it can reply. It doesn’t write it down.
There is no user database. You are your keys, and your keys stay with you.
For a moment
What it sees while it works, and for how long.
When you sign in to a site through us, our server checks your proof and passes the site a token. To do that, it briefly holds the site’s name and the key you use there.
- In memory only. Never on disk, never in a log.
- Gone within a minute. Your key and the site’s name, together, are deleted as soon as the site collects its token, or after one minute if it never does.
- The request itself names the site but not you. It goes when you’ve proved your key, or after ten minutes at most.
- Two short-lived cookies. They hold a random number that ties the steps of one sign-in together, and nothing about you. They go when you’ve proved your key, or after ten minutes at most. The cookie policy lists them.
- Having a document witnessed? The details from its chip are checked in memory, for the few seconds the check takes, then dropped. Never your photograph.
- Sometimes not even that. A site can take your proof straight from your browser. Then our server isn’t sent your key at all.
One honest limit: like any computer, our server doesn’t scrub its memory the instant something is deleted. Someone who had already broken into it could watch sign-ins as they happen. That’s why we work so hard to keep it secure, and why nothing is ever written down.
Locked away
What we keep, and why we can’t read it.
Some things need to be kept somewhere so you can get back in on a new phone or laptop. We keep them for you, locked:
- Your keyring: your personas, locked so that only your passkey opens it.
- Each recovery code’s copy of its persona, locked so that only that code opens it.
- Your own record of where you’ve signed in and what you’ve agreed to share.
- Messages between your devices, when they keep each other up to date.
Your device locks each of these before it sends it, with a key that comes from your passkey, your recovery code or your secret. We never get those, so we can’t unlock them. Each copy is filed under a name made from that key too, so we can’t tell whose it is, or that two belong to the same person.
Backups. Every hour, a copy of this store goes to Hetzner, in its data centre in Helsinki, Finland. We lock it again before it leaves our server, so Hetzner holds only what it can’t read. Inside, they’re still the same locked copies that we can’t read either. Copies are kept for up to about six months, then deleted. The privacy policy names everyone who helps us.
Your passkey
What your passkey provider can do.
Your passkey is kept by a passkey provider: Google Password Manager, Apple’s iCloud Keychain, a password manager, or kivi on your phone. It’s the key that opens your keyring.
- It doesn’t see your keys. Your passkey gives a secret only on your device, when you use it, and only for wellknown.id.
- It does see the passkey’s name. By default that’s “wellknown.id” and a short code, never your name or your personas’ names, unless you choose to add one.
- It decides whether your passkey keeps working. If your account with it is locked or closed, or it loses or deletes the passkey, that way back in is gone.
- You trust its software, as you do with every passkey it keeps for you.
So your wellknown.id should never depend on one company. Keep a second way back in:
- A recovery code for each persona, printed or in a password manager. We offer one as soon as you start.
- kivi on your phone, which can keep your passkey itself, in the phone’s secure hardware, so you needn’t use Google or Apple at all. kivi is still in testing: see Get kivi.
More in Your key, your seal.
What you trust us for
The pages we send you.
Your keys are opened on your device, by wellknown.id’s own pages, which your browser fetches from our server. Whoever controls what our server sends could change those pages, and a changed page could ask for your keys. This is true of every website, and no design that runs in a browser can avoid it. So that’s where we put our effort:
- Builds anyone can repeat. Each release is built so that building it again from the same source gives exactly the same files. Our source code isn’t public yet; when it is, anyone can check.
- Signed releases. Every file of a release is listed by its fingerprint, and the list is signed with a key we keep offline, away from the server.
- A public log. Each release’s list goes in our release log, which only ever grows.
- Your browser checks the scripts. Each page names the fingerprint of every script it loads, and your browser refuses a script that doesn’t match.
- kivi checks the pages. kivi fetches our pages itself and compares them with the signed log. If they differ, it warns you, and won’t connect your devices or sign in for another device until they match again.
The limits, plainly: kivi sees what our server sends kivi, not what it sends your browser. There’s no independent copy of the log yet. And kivi on Android and iPhone needs a new build for its check; kivi on the web checks our pages today.
What sites learn
A key made just for them.
- A different key for every site. Your device makes one for each site you use. Two sites can’t tell they’ve met the same person by comparing keys.
- A different key for every persona. Your work and home personas are two separate accounts at a site, unless you choose to join them.
- That you proved you hold the key, just now. Nothing else: no name, no email address, no password.
A site still learns what you tell it, and what every browser shares with every site, such as your IP address. wellknown.id can’t change that. See who learns what when you sign in.
If the worst happens
If someone broke into our server.
We plan for it. Here is what they would and wouldn’t get.
They wouldn’t get:
- a list of our users, because there isn’t one;
- who signed in where, at any time before they broke in, because we don’t keep it;
- names, email addresses, dates of birth or passwords, because we never have them;
- anyone’s keys or secret;
- anything in our store they could read: your keyring, your recovery copies and your records are locked with keys we don’t have.
They could:
- change the pages we send, to try to take the keys of people who sign in while the change lasts. That’s the risk the checks above are there to catch: browsers refuse scripts that don’t match, and kivi warns you;
- watch sign-ins as they happen, in memory, for as long as they stayed in;
- use our signing keys to make tokens sites would accept as ours, until we replaced them. Sites that take your proof straight from your browser don’t rely on those keys. The same goes for our witness’s key, which vouches for documents;
- copy our locked store, and see roughly when copies are written. Without your passkey or recovery code, it stays locked.
What they could do is act, for a while. What they couldn’t do is take a store of facts about people, because we don’t have one. A court order, or a dishonest insider, would find the same.
More
Where to read on.
wellknown.id is in development. This page describes what’s built today, and says where something isn’t yet.