FAQ
Do I need my own domain?
You need a domain, but it does not have to be your own. Your company's domain, or any domain that someone manages for you, works too. Whoever manages the domain publishes information about its users and their devices in DNS records. They can also delegate a subdomain such as team.example.com to you.
Can I use my email address as my identifier?
Yes, if you can edit the DNS records of its domain. Email and triauth use separate records and do not interfere with each other. You can also choose any other name at your domain.
DNS is not secure. How can it hold my keys?
Websites read your records through several independent resolvers and only trust what all of them agree on. With DNSSEC on your domain, the records are cryptographically signed, and websites see that. Compare it with today: your password reset already depends on DNS and email, without any of these checks.
Private keys in a browser?
The browser creates the default key as non-extractable, so no script can read it, including the authenticator itself. You can add a passphrase, a security key, or biometrics on top. Each device has its own keys, and deleting one DNS record revokes a device. Meanwhile, the session cookies that attackers steal every day sit in the same browser with no protection at all.
Why not just passkeys?
Passkeys on their own give you a separate credential per website and no identity that you own across websites. Triauth adds the portable identity, public revocation, and signatures you can reuse. The two combine well. Your triauth authenticator can also use a passkey, biometrics, or a security key to authenticate you to websites.
Can a fake website phish me?
There is no password to type. A fake website can only send you to your own authenticator, which shows the address of the website that asked, and signs a response that only works for that website.
Whoever controls my DNS controls my identity. Is that a problem?
Yes, and it is the same today. Whoever controls your DNS controls your email, and with it every password reset. Triauth makes that trust visible, and lets you host everything yourself.
What if I lose my domain?
Your domain is the root of your identity. If it expires or is transferred away, you can no longer sign in anywhere with identifiers at it, and whoever registers it next can publish records for them. Email at your domain has carried the same risk for years, and the protection is the same: turn on auto-renew and keep the payment method and contact details current, protect the registrar account with two-factor sign-in and a transfer lock, and choose a registrar for its reputation and support rather than its price. For an organization, register the domain to the company, not to an employee. If you want the domain under the law of your own country, a country-code domain such as .uk from a registrar in your country is a reasonable choice, with rules that vary by country.
Can people see who has an account at my domain?
In private mode, the default, your identifier does not appear in DNS. The records are published under a label that only your lookup code can derive. In public mode, the identifier is visible, which suits public profiles and directories.
What if I lose my device?
Delete its records from your DNS, and the device can no longer sign in anywhere. Sign in from another registered device, or register a new one.
What if auth.triauth.org disappears?
Your domain's record decides which authenticator you use, and the authenticator is a set of static files. Host your own copy and point your record at it. Your keys are tied to the authenticator's address, so you register your devices again after a switch.
Does it work on phones?
Yes, in any modern browser. Register the phone's browser as its own device. On iPhone and iPad, use the authenticator regularly or keep another device registered, because Safari may clear stored data after a week without use.
How much does it cost?
The hosted authenticator and everything else we run at triauth.org are free of charge under the Terms of Service. The triauth-js library is open source under the Apache 2.0 license. The triauth-authenticator is available under the Elastic License 2.0, which lets you run it for yourself or your organization.
Why would a website add triauth?
Sign-in without passwords to store or reset. Single sign-on for business customers where the setup is "enter your domain". Session checks that catch stolen sessions. Signatures and attestations for more than login.
Is triauth ready for production?
Triauth is in public beta. The protocol, the library, and the authenticator are versioned, tested, and documented, and the project welcomes reports.