Self-host the authenticator
The Triauth Authenticator is a set of static files. It has no backend and no server-side database. Any web server or static hosting service can serve it. The triauth project serves a hosted authenticator at auth.triauth.org, but you are encouraged to self-host your own instance.
Triauth Authenticator on GitHub
Why run your own
- Your organization keeps every part of sign-in under its own domain.
- You control the code that runs where your keys are kept, and you can review every line of it.
- You control updates and availability.
Why stay with auth.triauth.org
- There is nothing to install, update, or keep online. The triauth project maintains the hosted copy.
- Your keys are created and kept in your browser either way. The hosted copy only delivers the application files, and it holds no accounts and no data about you.
- Your domain's record decides which authenticator you use, so you can move to your own copy later. You then register your devices again with the new authenticator.
- A self-hosted copy that falls behind on updates, or loses its security headers or its certificate, is a weaker place for your keys than the hosted copy. Run your own when you can look after it.
What you need
- A host name of its own, for example
auth.example.com. The application must be served at the root of that host, over HTTPS. A path such asexample.com/auth/does not work. - A web server or hosting service that sends the security headers that ship with the application. They stop other pages from embedding the authenticator, and they limit what its pages may load.
- A way to update it when new versions are released.
Get started
The source code, the releases, and self-hosting instructions are published on GitHub.
Once you set up your self-hosted instance, change your domain's record to name your new host:
dns
example.com. TXT "triauth auth.example.com mode=private"Your devices keep their keys at the authenticator's address. After the switch, set up each device again at the new address and publish its new records. See Your domain's record.
Keep it safe
- Use the host name for nothing else.
- Update the application when new versions are released.
- Keep the security headers in place when you change the server configuration.