Passwordless authentication for the modern web
No more passwords - sign up and log in to websites with just a click.
Free, decentralized, and truly yours.

How it works
Create your identifier
Click “Get started”, choose a name under a domain you control, and add a few lines to your domain's DNS settings. They list this device as yours.
Type it on any website
On a site with a “Sign in with triauth” button, enter your identifier. There is no password field. The website looks up your domain and sends you to your authenticator page.
Approve on your device
When you approve, your browser signs the request, and the website checks the signature against the list of your devices in your DNS settings. You sign in. Scammers get nothing they can reuse.
For developers
Add “Sign in with triauth” in an afternoon
Two calls to one function and you're done. No vendor accounts or centralized registries in the loop. Your app verifies the user's signature against public DNS records itself.
Open-source, zero runtime dependencies, TypeScript types included, runs in Node.js 18+ and modern browsers.
import * as Triauth from 'triauth';
// 1. Start: send the user off to approve a challenge
const start = await Triauth.authenticate({
identifier: 'john@example.com',
callbackUrl: 'https://yourapp.com/callback'
});
// keep start.challenge, redirect to start.redirectUrl
// 2. Finish: verify the response the user brings back
const result = await Triauth.authenticate({
challenge: start.challenge, response
});
if (result.authenticated) {
// signed in as result.identifier
}Free, decentralized, and truly yours.
Your identity lives in your own domain, not in an account that someone else can lock, track, or sell. The protocol, the client libraries, and the authenticator are all public, and you can easily run every piece yourself.