Devices and keys
In triauth, a device is one browser on one computer or phone that you have set up with your identifier. Each device has its own keys. Your identity records list every device by name, with its public keys.
One device, one or more keys
When you set up a device, the authenticator creates a browser key. The browser's own cryptography generates it and marks it as non-extractable. Such a key can sign, but the browser does not allow it to be copied, not even by the authenticator itself.
You can add more keys to the same device:
| Key | Factor | What happens at sign-in |
|---|---|---|
| Browser key | Something you have | Signs without asking you anything |
| Passphrase key | Something you know | Asks for your passphrase, then signs |
| Passkey, security key, or biometrics | Something you have, or something you are | Asks for a touch, a fingerprint, a face, or a PIN, then signs |
Adding a passphrase or a security key gives you multi-factor sign-in that the website can verify against your DNS records.
Keys that ask you something typically do not take part in silent requests, such as a background check that you still hold your keys. Keys that sign without asking you, such as the browser key, answer those on their own.
How devices appear in DNS
Each key is one record. The device name and the numbers in brackets group the keys of one device:
dns
john._at.example.com. TXT "key laptop[1/2]:BFj4O8oJN4mr-IXtikZpDqTarqn_ZMuKbpdqxqKxwV9szveo…"
john._at.example.com. TXT "key laptop[2/2]:BLstmtxB6ceFUwjORLMlWfFmZ9XtqMQeUGs5iaCXkCQVUh-l… type=webauthn-es256 use=attest,auth,sign"
john._at.example.com. TXT "key phone[1/1]:BJSnllMPgReHvUqe7CYElsmTx8hLdYWVyneqif1DP58WlhIt…"A key record has the following parts.
| Part | Meaning |
|---|---|
key | Marks a key record. |
laptop | The device name that you chose in the setup. All records with the same name belong to one device. |
[1/2] | The position of this key, and the number of keys of the device. A device is complete when every position is published exactly once. |
BFj4O8oJ… | The public key. |
type=webauthn-es256 | The type of cryptographic algorithm used with the key. Optional. |
use=attest,auth,sign | The requests the key takes part in: auth, ping, sign, stamp, and attest. Optional. Without it, the key takes part in all of them. |
uv=required | Only for security keys and biometrics. Requires that the key verified you, for example with a PIN or a fingerprint, before it signed. Optional. |
Websites identify a device by a fingerprint of its name, its keys, and their recognized options. When you rename the device, or add, remove, or change a key, it becomes a new device to them.
Websites use a device only when all of its records are well formed. One malformed record, for example a typo in an option or a wrong number in the brackets, makes the whole device unusable until you fix it.
Add a second device
- Open your authenticator in the other browser.
- Start the setup with the same identifier. In private mode, choose that you already have a lookup code, and type it.
- Give the device a name that is not in use yet.
- Publish the records that the setup shows, next to the records of your other devices.
Do this soon after your first device. With two devices, a single lost device or wiped browser does not lock you out.
Revoke a device
Delete the device's key records from your DNS. Once the TTL of the records has passed, the device cannot sign in anywhere. Websites that re-check sessions end the device's sessions at their next check.
Do this when a device is lost or stolen, when you stop using it, or when someone leaves your organization.
Keep your keys
Your keys are stored by the browser, and anything that removes the browser's data removes them. The common causes are:
- Clearing the site data of your authenticator, or resetting the browser profile.
- Automatic cleanup. Safari on iPhone, iPad, and Mac may remove stored data after a week without use. Other browsers may remove it when storage runs low.
The authenticator asks the browser to keep its storage. Help it by bookmarking the page, by installing it as an app when your browser offers that, and by using it regularly.
If keys are gone, set up the device again and publish its new records. Delete the old records.
Replace the keys of a device
Delete the identity on the device, run the setup again with a new device name, and publish the new records. Then delete the records of the old device name.