Public and private mode
Your identity records are public. Anyone who knows where to look can read your device names, their public keys, and your public profile. The mode of your domain decides how easy it is to find them.
Where the mode is set
The mode is an option of your domain's record, the triauth TXT record at your domain:
dns
example.com. TXT "triauth auth.triauth.org mode=private"The option takes one of two values, private or public. private is the default. When the option is missing, the domain runs in private mode. The mode applies to every identifier at the domain. See Your domain's record.
Public mode
In public mode, the records are published under a name built from your identifier. For john@example.com, they are at john._at.example.com. Anyone who knows or guesses your identifier can check that it exists and read its records.
dns
example.com. TXT "triauth auth.triauth.org mode=public"
john._at.example.com. TXT "key laptop[1/1]:BHAILL142prn8rQsHm5ZlMPUFeMc6niVXXIM8biVY3HPj…"
john._at.example.com. TXT "name John Doe"Choose public mode when you want to be found, for example for a public profile or a company directory.
Private mode
In private mode, the default, the records are published under a label derived from your identifier and a lookup code. Without the code, nobody can tell that john@example.com exists, or which records belong to it. The records also include a commit entry that ties them to your code.
dns
example.com. TXT "triauth auth.triauth.org mode=private"
_4GIBDU53B3._at.example.com. TXT "commit 3Q7YSpb3MLMRaQ20VZBUfoySyM4vQrHMfIIuAxER3_s"
_4GIBDU53B3._at.example.com. TXT "key laptop[1/1]:BHAILL142prn8rQsHm5ZlMPUFeMc6niVXXIM8biVY3HPj…"Choose private mode for personal domains, and for organizations that do not want to publish a list of their members.
The lookup code
The lookup code is a 16-character code. The authenticator creates it the first time you set up an identifier at a private-mode domain. It looks like K7QJ-3FB9-M2WZ-X0C4.
- You need it to set up the same identifier on another device. The setup asks for it.
- Each device you set up keeps a copy. Open the identity menu and choose Show lookup code.
- Websites you sign in to receive it with your signed response, so that they can check your records later.
- Sharing the code lets someone read your records. It does not let anyone sign in as you.
Keep the code with your other important notes. If you lose it, and no registered device has a copy, set up the identifier again as a first-time setup. The authenticator creates a new code, and you publish new records under a new label. Delete the old records afterwards.
Switching modes
Change the mode option in your domain's record. Then set up every identifier again, so that its records move to their new names, and delete the records at the old names.