DNS records
All triauth data in DNS is in TXT records. Each record starts with a keyword, followed by a value, and sometimes by options in the form key=value at the end of the record. Verifiers read each record on its own. They ignore records with an unknown keyword, which permits additions to the protocol.
Where records go
| Records | DNS name | Example |
|---|---|---|
| The domain record | The domain part of the identifier | example.com |
| Identity records in public mode | The username, then ._at., then the domain | john._at.example.com |
| Identity records in private mode | An underscore, a label derived from the identifier and the lookup code, then ._at., then the domain | _4GIBDU53B3._at.example.com |
The domain record
The domain record connects a domain to triauth. Verifiers read it first, to find the authenticator for every identifier at the domain and to learn how to derive the names of the identity records.
dns
example.com. TXT "triauth auth.example.com mode=private include=any"| Part | Meaning |
|---|---|
triauth | The keyword. A domain must have at most one such record. |
auth.example.com | The host name of the authenticator. No scheme, port, or path. The authenticator's address is https:// followed by this name. Labels that start with xn-- are not permitted. |
mode=private | Where identity records are published. private (the default) or public. A different value makes every identifier at the domain unresolvable. |
include=any | The delegation policy. any (the default), local, none, or a comma-separated list that can contain local and domain names. See Delegation. |
Unknown options are kept but have no effect. See Your domain's record for how to publish and change this record.
Key records
Key records publish the public keys of an identity, grouped by device. Verifiers check every signature against them. A device is revoked by deleting its key records.
dns
john._at.example.com. TXT "key laptop[1/2]:BFj4O8oJN4mr-IXtikZpDqTarqn_ZMuKbpdqxqKxwV9szveo…"
john._at.example.com. TXT "key laptop[2/2]:BLstmtxB6ceFUwjORLMlWfFmZ9XtqMQeUGs5iaCXkCQVUh-l… type=webauthn-es256 use=attest,auth,sign"| Part | Meaning |
|---|---|
key | The keyword. One record per one cryptographic key. |
laptop | The device name. Lowercase letters, digits, and hyphens. All records with the same name form one device. |
[1/2] | The position of this key and the number of keys of the device. The number must be the same in every record of the device. The device is complete when every position is present. |
BFj4O8oJ… | The public key, in base64url. |
type=webauthn-es256 | The key type. es256 (the default), ed25519, webauthn-es256, or webauthn-ed25519. |
use=attest,auth,sign | The request types the key signs, from attest, auth, ping, sign, and stamp. The default is all five. |
uv=required | Requires user verification, such as a PIN or a fingerprint. Permitted on WebAuthn key types only. |
Verifiers use only complete devices. One malformed record makes its whole device invalid. Unrecognized options make the record malformed, with the exception of options that start with x- which are considered experimental and allowed. A verifier identifies a device and computes deviceTag by a digest of its name, its key count, its keys, and their recognized options with defaults applied.
Profile records
Profile records publish public details of an identity. Websites receive them with every result and can show them next to the identifier.
dns
john._at.example.com. TXT "name John Doe"
john._at.example.com. TXT "initials JD"| Part | Meaning |
|---|---|
name | The display name of the identity. |
initials | The initials of the identity. |
x-… | An extension field, kept as published. |
Profile values are percent-decoded UTF-8 text. A keyword that appears in more than one record is dropped. Verifiers deliver the values as they are, so websites must escape them before display.
Groups records
Groups records publish the groups that an identity belongs to. Websites receive the list at sign-in and at every session check, and can map it to roles.
dns
john._at.example.com. TXT "groups admins,billing"| Part | Meaning |
|---|---|
groups | The keyword. An identity can have several such records. |
admins,billing | Group names, separated by commas. Lowercase letters, digits, and hyphens. |
The group set of an identity is the union of all its groups records. Verifiers deliver each name qualified with the domain, such as admins@example.com. A record with a malformed name is ignored as a whole. Options are not permitted. See Groups.
Include records
Include records grant another identity, the actor, the right to sign on behalf of this identity with the actor's own keys. Deleting the record revokes the grant.
dns
john._at.example.com. TXT "include assistant@example.com scope=app.example.com use=sign"| Part | Meaning |
|---|---|
include | The keyword. One record per grant. |
assistant@example.com | The actor: an identifier, or its identity domain (e.g., assistant._at.example.com, _AD7FDEY67C._at.example.com). |
scope=app.example.com | Required. The host names of the websites where the grant applies, separated by commas, or any. Host names must match exactly. |
use=sign | Optional. The request types the grant covers, from the same ones as for keys. The default is all types. |
A record without scope, or with an unknown option, is ignored. The domain's include policy decides which grants are admitted. A grant names an identity, not a device. Every device of the actor can sign under it. See Delegation.
Commit records
The commit record binds a private-mode identity to the lookup code its records were derived from. It prevents records of two identities from being mixed when their derived labels collide.
dns
_4GIBDU53B3._at.example.com. TXT "commit 3Q7YSpb3MLMRaQ20VZBUfoySyM4vQrHMfIIuAxER3_s"| Part | Meaning |
|---|---|
commit | The keyword. Works in private mode only. |
3Q7YSpb3… | A digest that binds the records at this name to the lookup code they were derived from. |
An identity in private mode must publish exactly one commit record, otherwise it is treated as non-existing. The authenticator computes the value of this record during setup.
Practical notes
- DNS providers can split a long value into several strings. Verifiers join them without a separator.
- Verifiers read the records through several resolvers and keep only the records that all resolvers return. See Configuration.
- There is no record for the private key. Nothing secret is published.
- Deleting records is how you revoke: a device, a delegation, a group membership, or a whole identity.