Signatures and stamps
Sign-in is one use of triauth. The device keys can sign anything you put in front of the user, and anyone can verify the result against the user's DNS records.
Sign: the user reviews and signs
Triauth.sign sends the user to their authenticator with a message and, if you want, files to review. The user reads the message, opens the files, and signs. You get back a signature that you can store, forward, and verify later.
Use it to record that a user accepted terms, approved an order, or signed a document.
API reference:JavaScript
Stamp: a silent signature
Triauth.stamp obtains a signature over a short message without interaction. Use it when another party needs proof that the user is signed in with you, for example to pass a session to a partner service.
API reference:JavaScript
Verify
Triauth.verify checks a signature against the signer's current DNS records, with no session and no challenge. Anyone with the message and the signature can do this, including a third party you forward them to.
API reference:JavaScript
Before you rely on a signature
- A signature verifies as long as the signer's keys are published. If you must verify years later, store the DNS records with the signature, or use a DNS history service.
- Signatures and stamps are transferable proofs. They are not bound to one request. If a signature must be usable only once, put a random single-use value inside the message, and reject values you have seen before.