Public demo — don't enter real personal data.

Security

Built so there's little to steal.

Every statement on this page describes how YourID actually works today — including what isn't finished yet.

Last updated: 1 October 2026

passwords stored
0passwords stored
lifetime of an email code
10 minlifetime of an email code
lifetime of a sign-in code for a service
60 slifetime of a sign-in code for a service
longest a service stays connected on one sign-in
30 dayslongest a service stays connected on one sign-in

How a sign-in travels

Your secret stays home. Only proof travels.

When a service asks “who is this?”, three parties take part. Watch what moves between them — and what never does.

Your device

Never leaves

  • Private key of your passkey
  • Face, fingerprint or device PIN

YourID

  • Public key only
  • Email codes, hashed
  • Signing key, encrypted
  • Database in the EU (Ireland)
Request + PKCE

The service

shop.example

age_over_18…
  • Only the claims you approved
  • Signed by YourID

Data

What we keep. What we never have.

The safest data is data we don't hold. Here is the full picture of what sits in our database.

What we store

  • Your email address

    To find your account and send sign-in codes.

  • Your passkeys' public keys

    They can check a signature, but can't make one.

  • Email sign-in codes — as hashes

    Valid for 10 minutes; we can check a code, not read it back.

  • Refresh tokens and app secrets — as hashes

    Useless to anyone who copies the database.

  • Which services you connected

    And exactly what you allowed each one to see.

  • Sign-in sessions and an activity log

    Including browser and IP address, so you can see them and sign out anywhere.

  • Profile details you choose to add

    Nothing is shared unless you approve it.

What we never store

  • Passwords

    There aren't any. Nothing to guess, reuse or leak.

  • Your passkey's private key

    It stays on your device or in your platform's own passkey sync.

  • Your face or fingerprint

    Your device checks those itself. We only learn that the check passed.

  • Readable sign-in codes or tokens

    Only their SHA-256 hashes.

  • The signing key in plain form

    It is stored encrypted with AES-256-GCM.

  • Identity documents

    Document verification isn't live yet, so no document is processed at all.

Protections

Twelve things doing the work.

Each one in plain words — with the technical name underneath, for developers who want to check.

01

No passwords

You sign in with a passkey, so there is no password to phish, guess or reuse.

WebAuthn / FIDO2 passkeys

02

It has to be you

Every passkey sign-in requires your face, fingerprint or device PIN, and our server checks that it happened.

User verification (UV) enforced server-side

03

Challenges work once

Each sign-in challenge can be used a single time and expires after five minutes.

Single-use WebAuthn challenges · 5-min TTL

04

Email codes, contained

Codes are stored hashed, expire in 10 minutes, allow 5 tries, and requesting a new one retires the old.

SHA-256 · timing-safe compare · per-IP and per-address rate limits

05

Sessions you can end

Your session is a signed token backed by a server record, lasts at most 7 days, and you can sign out everywhere.

Signed HttpOnly cookie + revocable session row

06

Standard sign-in for services

Services connect through the open standard, and every request must be locked with a one-time proof.

OpenID Connect · authorization code flow · PKCE S256 required

07

Exact return addresses

We only send you back to an address the service registered in advance, character for character.

Exact redirect-URI match · https only (localhost excepted)

08

Sign-in codes expire fast

The code a service redeems works once, within 60 seconds. A second attempt revokes what was issued.

Single-use auth codes · 60 s TTL · replay revokes tokens

09

Answers are signed

Services can verify that an answer came from YourID and wasn't changed on the way.

RS256-signed ID tokens · published JWKS

10

Long-lived access, renewed safely

Each renewal swaps the token for a new one; if an old one is reused, the whole chain is cancelled. Thirty days at most.

Refresh-token rotation · reuse detection · fixed 30-day family lifetime

11

Consent counts right now

A service only gets what you currently allow. Withdraw consent and its existing tokens stop working.

Effective scope = token scope ∩ current consent

12

Keys locked, database closed

Our signing key is encrypted, app secrets are hashed, and the EU database only answers our own servers.

AES-256-GCM · hashed client secrets · RLS on every table, no policies

Threats

Attacks, and what stops them.

No system is unbreakable. These are the attacks we designed against, and the specific mechanism that answers each one.

The attack

Phishing

A fake site that looks exactly like YourID asks you to sign in.

What stops it

A passkey is bound to YourID's real domain. Your device won't use it on a look-alike, and our server rejects signatures made for any other origin.

WebAuthn RP ID + origin binding

The attack

A stolen database

Someone gets a full copy of our data.

What stops it

There are no passwords to crack. Public keys can't sign anyone in, and codes, tokens and secrets are only stored as hashes.

Public-key credentials · SHA-256 hashes · encrypted signing key

The attack

A stolen refresh token

An attacker copies the token a service uses to stay connected.

What stops it

Tokens rotate on every use. When an old one shows up again, the entire family is revoked — and none lives beyond 30 days.

Rotation + reuse detection

The attack

An intercepted code

Someone grabs the one-time code on its way back to the service.

What stops it

Without the secret proof the real service holds, the code is worthless. It expires in 60 seconds and works only once.

PKCE S256 · single-use 60 s codes

The attack

A fake “bank” app

A malicious app registers itself with a trustworthy-sounding name.

What stops it

The consent screen always shows the website you'll be sent to, and apps registered by outside developers carry an “Unverified app” label.

Destination host shown · unverified badge · exact redirect URIs

The attack

Clickjacking

Another site hides our consent screen in an invisible frame to trick your click.

What stops it

No YourID page can be shown inside another website.

CSP frame-ancestors 'none' · X-Frame-Options: DENY · HSTS

The attack

Guessing an email code

A script tries code after code.

What stops it

Five attempts per code, ten minutes to use it, and limits per network address and per email address.

Attempt counter · DB-backed rate limits (fail closed)

Honest status

Where we are today.

Security pages usually only list strengths. Here is what you should also know.

YourID is in private beta

We're admitting people gradually and still changing things.

No independent audit yet

There has not yet been an external security audit or penetration test. We intend to commission one before YourID becomes generally available.

Document verification isn't live

We can't check identity documents yet. Until we can, no document is processed.

Responsible disclosure

Found something? Tell us.

If you find a vulnerability, email us. Good-faith research is welcome here.

security@yourid.org
  • We acknowledge reports within 48 hours.
  • We will not take legal action against good-faith research.

Try it for yourself.

Join the beta, sign in with a passkey, and see on your own screen what a service gets to see.