You, on wellknown.id
Your records are kept encrypted with keys only your wellknown.id gives, and read here in your browser; every device where you unlock a persona shares its records. wellknown.id's servers can't read them: not your personas, not where you sign in, not which key each site knows you by.
Your personas
Each persona is a wellknown.id of its own: sites see each as a different person, and can't tell they're both you. The default signs you in at sites you haven't used before. Names are only for you: no site sees them.
Loading…
The recovery code for . Write it down, or keep it in a password manager: with it, you can get this persona back on any browser, with its sign-in keys and records, even if your passkey is gone. wellknown.id can't show it again.
·
What each way back brings: your passkey brings your personas to any device, with their sign-in keys and records; a recovery code brings its one persona, with its sign-in keys and records. Neither brings secrets, documents or bonds kept in kivi: those stay on the devices that hold them, and documents are read again from their chips on each device.
Where you've signed in
Loading…
Your ways back in
A second passkey is a second way back in: another password manager, a phone, or a security key. Your browser won't make it where your first one is kept.
wellknown.id is forgotten on this browser. Your passkey, or a persona's recovery code, brings your personas back whenever you want them here.
kivi, on your phone
kivi reaches the same personas and records with your passkey, or a persona's recovery code: nothing to pair. It also keeps documents and secrets, on the device that holds them: those don't come back with a passkey or a code, and kivi keeps them out of a phone's backups. Get kivi.
Take a copy
Your sign-ins as consent records (ISO/IEC TS 27560, in the W3C Data Privacy Vocabulary's JSON-LD).