Glossary
DNS terms
Domain
A domain is a name on the internet, such as example.com. You rent it from a registrar, a company that sells domain names, and you renew it every year or so. As long as you keep it, you decide what it points to and what information is published under it. Your triauth identifiers end with your domain, for example john@example.com, and that is what makes them yours.
Registrar
A company that sells and renews domain names, such as Cloudflare, Namecheap, or GoDaddy. Many registrars also host your DNS records and provide the DNS panel. You can keep the domain at one company and its DNS records at another.
Subdomain
A name under your domain, such as team.example.com or auth.example.com. You create subdomains in your DNS panel, at no cost. Triauth uses subdomains for the address of the authenticator and for identity records, and a subdomain can carry identifiers of its own, for example john@team.example.com.
DNS
DNS is short for Domain Name System. It is the public directory of the internet. When you type example.com into a browser, DNS is what tells the browser which computer to contact. Every domain has entries in it, and the owner of the domain decides what they say. Triauth stores its information there, so that any website in the world can look it up without asking anyone's permission.
DNS record
A DNS record is one entry in the DNS for a domain. A domain usually has several: one says where its website is, another where its email should go. Each record has a type that says what kind of information it holds. Triauth uses records of the TXT type for everything it publishes.
TXT record
A TXT record is a DNS record that holds a short piece of text instead of an address. Many services use TXT records to prove that you control a domain or to publish settings, and so does triauth. You add one in your DNS panel by choosing the type TXT, giving it a name, and pasting the text. The authenticator shows you the exact text to paste.
DNS panel
The DNS panel is the page on your DNS provider's or registrar's website where you manage the records of your domain. It looks like a table with a type, a name, and a value for each record, and it has buttons to add, edit, and delete records. If someone else manages your domain, for example your IT department, they use this panel on your behalf.
Zone file
A text file that lists DNS records in a standard format. Many DNS panels can import one, which saves typing records by hand. The setup in the authenticator can export the records of a device as a zone file.
TTL
TTL is short for time to live. It is a number of seconds on each DNS record that says how long other computers may keep a copy of the record before they ask for it again. A long TTL makes lookups faster. A short TTL makes changes reach everyone sooner. You set it in your DNS panel next to the record, and many panels offer a default such as one hour.
DNSSEC
DNSSEC adds a digital signature to the DNS records of a domain, so that anyone who reads them can check that they came from the domain's owner and were not changed on the way. Without it, a forged answer is hard to tell from a true one. Many registrars turn it on with one switch. Websites that support triauth report whether your records were protected by it.
Resolver
A resolver is a computer that looks up DNS records on behalf of others. Your internet provider runs one, and companies such as Cloudflare and Google run public ones. A resolver keeps copies of the records it fetched, for as long as their TTL allows, so that it can answer the same question again without asking the domain. Websites that support triauth ask several independent resolvers and accept a record only when all of them agree, which makes a single forged answer harmless.
Keys and signatures
Key pair
Triauth identifies a device by a pair of keys that belong together, a private key and a public key. They are long random numbers, created during setup on your device, or on a security key that you attach to it. What the private key signs, the public key can check. Each device you set up gets a pair of its own.
Private key
The half of a key pair that stays secret. It is kept on your device, in the browser's storage or in security hardware, and it is not sent anywhere. When you approve a sign-in, the private key signs the request. Whoever holds a private key can sign as you, which is why it is kept out of reach, and why you revoke a device by deleting its records.
Public key
The half of a key pair that anyone may see. It cannot sign anything. It can only check a signature made with the matching private key. Triauth publishes your public keys in your DNS records, and websites read them there to verify your sign-ins.
Non-extractable key
A private key that the browser keeps for itself and does not hand out to any program, not even the authenticator. The browser uses it to sign when asked, and that is all. The browser key that the authenticator creates for every device is of this kind.
Digital signature
A short piece of data that a private key produces for a message, such as a sign-in request. Anyone with the public key can check that the signature belongs to that message and to that key, and that the message was not changed. Every triauth response is a digital signature. It proves who signed without revealing the private key.
Browser key
The key that the authenticator creates for every device at setup. The browser's own cryptography generates it and keeps it as a non-extractable key in the browser's storage for the authenticator's address. It signs without asking you anything, so it counts as something you have. Anything that removes the browser's data removes it.
Passphrase key
A key that the authenticator stores encrypted with a passphrase you choose. It is unlocked only for the moment it signs, after you type the passphrase. It adds something you know to a device.
Security key
A small hardware device, such as a USB key, or the security chip built into a phone or computer, that holds a key and signs only after you touch it or unlock it. It is designed so that the key stays inside the hardware. It adds something you have, or something you are, to a device.
Biometrics
Confirming who you are with a fingerprint, a face, or another measurement of you, checked by your device, for example with Touch ID, Face ID, or Windows Hello. When a triauth device uses biometrics, the security chip of the device signs after the check succeeds. The device checks your fingerprint or face on its own and does not send it anywhere.
Passkey
A sign-in credential stored on your device or in a cloud keychain, associated with a specific website. Your triauth authenticator can create and use its own passkey as an additional authentication factor.
Multi-factor sign-in
A sign-in that needs more than one kind of proof: something you have, such as a key on your device, something you know, such as a passphrase, or something you are, such as a fingerprint. In triauth, every key of a device signs a request, so a device with a browser key and a passphrase key is multi-factor by itself, and websites can verify that against your DNS records.
Triauth terms
Identifier
The name a person or a service signs in with, in the form username@domain, for example john@example.com. It is lowercase. The domain part decides where the records are.
Domain record
The TXT record at a domain that starts with triauth. It names the authenticator for everyone at that domain and sets the mode. One per domain.
Authentication endpoint
The address of the authenticator for a domain, https:// followed by the host name from the domain record. Browsers are sent there to approve requests.
Authenticator
The application that holds a user's private keys and approves requests. The Triauth Authenticator is the reference application, hosted at auth.triauth.org and available for self-hosting.
Identity records
The TXT records that describe one identifier, published in the DNS of its domain. They list the devices of the identifier by name, each with its public key. They can also hold a public profile of the identifier, its groups, delegations, and other information. Websites read them to check that a sign-in comes from one of those devices. Anyone who knows where to look can read them as well.
Identity domain
The DNS name under which the identity records are published. In public mode it is the username, ._at., and the domain. In private mode it is a label derived from the identifier and the lookup code. The library reports it as identityDomain.
Mode
The mode option of the domain record. public publishes identifiers in DNS names. private, the default, hides them behind derived labels.
Lookup code
A 16-character code created at the first setup of an identifier at a private-mode domain. It is needed to find the identity records, and to set up more devices. It does not allow anyone to sign in.
Device
One browser on one computer or phone, set up with an identifier. A device has one or more keys, and a public device name that appears in the key records.
Device tag
A fingerprint of a device's published keys, computed by verifiers and returned to websites. It changes when the device's keys change. Under a delegation, it also covers the grant and the actor.
Key
A public key published in a key record, with a type and the request types it applies to. Kinds of keys on a device correspond to factors: a browser key, a passphrase-protected key, and a security key or biometrics.
Challenge
The request a website builds, encoded as one string. It names the callback URL, the request type, the identifier, a random value, the time, and the version.
Response
The signed answer from the authenticator, a signature envelope in one string. Websites verify it against the identity records.
Callback URL and base URL
The URL of the website that receives the response. Its base, the origin and the path up to the last slash, identifies the website in the authenticator and binds tokens to it.
Token
A secret that the authenticator issues to a website at sign-in, when the website asks for it. It allows a later background check, signature, stamp, or attestation for that website. Tokens change at every sign-in.
Extension
Extra data in a request, in the ext object, such as the callback method, a request for the private profile, a manifest, or a token request.
Actor and delegation
An actor is an identity that signs on behalf of another identity. The permission is a grant, published as an include record in the records of the identity that delegates. Verifiers report the actor next to the identifier.
Groups
Group names that an identity's records claim, qualified with the domain, such as admins@example.com. Websites can map them to roles.
Attestation and verification provider
An attestation is a claim about the user, such as "over 18", signed by a verification provider that the website trusts. A provider is a website with a triauth identity of its own.
Secure flag
The secure value in a result. It is true when DNSSEC-validating resolvers confirmed every record involved.
Public profile and private profile
The public profile is the name and initials published in the identity records. The private profile is the name, initials, and email address stored on the device, shared only with websites the user allows.
Relying party, website, verifier
The application that asks a user to sign in and verifies the response. This guide calls it the website, or your app.