Start

wellknown.id for developers

Sign-in where your users hold their own keys: one file on your domain, a script tag, and a standard OpenID Connect ID token. Guides, reference and the API.

What you get

A person signs in to your site with a key only they hold, made for your site alone. You receive an ordinary OpenID Connect ID token whose sub is that key, as a did:key. There's no client registration and no client secret: your client_id is your domain, and a small JSON file on it says where sign-ins may return.

  • No user database at wellknown.id. It keeps no accounts, no names, no email addresses, and no record of who signed in where.
  • A different key at every site. Two sites can't match their records of a person by key.
  • Standard where it can be. Discovery, the authorization code flow with PKCE, ID tokens signed with published keys: a stock OpenID Connect library verifies them.

Where to start

  • Getting started: sign-in in three steps, and verifying the token on your server.
  • The web SDK: the button, its options and its events.
  • How it works: per-site keys, personas, self-issued proofs, FedCM, and why the server keeps nothing worth stealing.

Reference

Guides

Status

wellknown.id is in development, in a preview: endpoints and formats may still change before launch. Each page says what works now and what's planned. The packages aren't published to npm yet; until they are, write to hello@wellknown.id for any file a page mentions.