Attestations
An attestation is a signed confirmation about the user from a third party you trust. You name what you want confirmed and which providers you accept. The user picks a provider, completes its check, and returns with the provider's signature bundled with their own.
Use it to replace a CAPTCHA, to confirm age, to confirm a role or a membership, or for any other claim that a provider can check.
Attest: collect attestations from providers you trust
Triauth.attest sends the user to their authenticator with the attestations you want and, for each of them, a label and the providers you accept. The authenticator shows each attestation to the user as a verification to complete, with your label, a choice of providers, and a Verify button. The user picks a provider, completes its check on the provider's site, and comes back with the provider's signature bundled with their own. You get back the result of each attestation.
API reference:JavaScript
What is verified
The attest result confirms that each attestation was signed by an identity at the domain of one of the providers you listed, and that the user's own signature is valid. It does not know what the provider checked. You choose the providers, and each provider defines what its signature means.
Anonymous by default
A provider receives the address of the user's authenticator, and it knows which check to perform from the address you listed for it. It does not learn the user's identifier unless it asks the user for it, or unless you include the identifier in the address. Include it only when the provider needs it, since the provider then learns who the user is.
When an attestation must belong to one specific user, use a provider that asks for the identifier and names it in its signature.
Providers
A provider is a website that checks something about the user, such as a CAPTCHA, an age, or a login to a system that knows them, and signs a statement that the check passed. You choose which providers to trust by listing their addresses, and each provider defines what its signature means.
The exchange has four steps:
- The user selects a provider and clicks Verify. The authenticator opens the provider's address. It gives the provider a return address and a digest of your request.
- The provider does its check. If it needs the user's identifier, it asks the user.
- The provider signs the digest with the keys of its own identity, which must be at the domain of the address you listed. It sends the browser back to the return address with the signature.
- The authenticator adds the provider's signature to the user's signature. It sends both to your callback URL.
The provider signs a digest of your request, so its signature is valid for this request only. The provider can also bind its signature to the user, the device, and your website.
Before you rely on an attestation
- Your provider list is your trust decision. The attest result confirms only that a listed provider signed. It does not know what the provider checked. List only providers whose check matches your claim.
- An attestation says that the check passed for this request. The provider may also bind it to the user's identifier, but it does not have to. For a claim that must apply to this user, such as an age check, use a provider that binds its signature to the user, and check that the result contains the binding.
- The
securevalue covers the records of the user and of every provider. When it isfalse, DNSSEC did not protect all of those records. You can check that any specific provider records were covered by DNSSEC by inspecting the result.