You, on wellknown.id

Your records are kept encrypted with keys only your wellknown.id gives, and read here in your browser; every device where you unlock a persona shares its records. wellknown.id's servers can't read them: not your personas, not where you sign in, not which key each site knows you by.

Your personas

Each persona is a wellknown.id of its own: sites see each as a different person, and can't tell they're both you. The default signs you in at sites you haven't used before. Names are only for you: no site sees them.

Loading…

What each way back brings: your passkey brings your personas to any device, with their sign-in keys and records; a recovery code brings its one persona, with its sign-in keys and records. Neither brings secrets, documents or bonds kept in kivi: those stay on the devices that hold them, and documents are read again from their chips on each device.

Where you've signed in

Loading…

Your ways back in

kivi, on your phone

kivi reaches the same personas and records with your passkey, or a persona's recovery code: nothing to pair. It also keeps documents and secrets, on the device that holds them: those don't come back with a passkey or a code, and kivi keeps them out of a phone's backups. Get kivi.

Take a copy

Your sign-ins as consent records (ISO/IEC TS 27560, in the W3C Data Privacy Vocabulary's JSON-LD).