Private beta · invite only
How it works
No password. Nothing shared without a yes.
From your first email code to the day you lose your phone: here's exactly what YourID does, what it keeps, and what never leaves your device.
Step by step
Five moments, start to finish.
- 1
Step 1 of 5
Create your YourID
Enter your email and we send you a 6-digit code, valid for 10 minutes. Then you create a passkey — and that's your account.
- The private key is generated on your device and stays there (or in your platform's passkey sync, like iCloud Keychain or Google Password Manager).
- You unlock it with your face, fingerprint or device PIN.
- YourID stores only the public key. There is no password at all — nothing to guess, reuse or leak.
- 2
Step 2 of 5
Sign in anywhere you see “Login with YourID”
The site sends you to YourID, you confirm with your passkey, and you're sent straight back. It's built on OpenID Connect with PKCE — the same open standard behind most “Sign in with…” buttons.
- No new account, no new password for each site.
- Your passkey only works on YourID's real address, so a look-alike site can't use it.
- 3
Step 3 of 5
See exactly what's asked — and decide
The first time a service asks, you see its name, the web address you'll return to, and every item it wants, listed one by one.
- Untick individual profile fields you'd rather keep to yourself.
- An age check returns only yes or no to “over 18” — never your date of birth.
- Nothing is shared until you tap Allow.
- 4
Step 4 of 5
Stay in control afterwards
Your dashboard lists every connected service and exactly which fields it can see. One tap revokes access — its tokens stop working immediately.
- An activity log shows your sign-ins and consents.
- Sign out other devices; add, rename or remove passkeys.
- Delete your account and your data is removed from our live database immediately.
- Data a service already received falls under that service's own privacy policy.
- 5
Step 5 of 5
Lost your phone? You're not locked out
Sign in on another device with a code sent to your email, add a new passkey there, and remove the lost phone's passkey in Settings.
- Using a synced passkey? It comes back on your new phone by itself.
- Once you remove the lost phone's passkey, it can never be used to sign in again.
Where your data lives
What YourID keeps — and what never leaves you.
A passkey is a pair of keys. One stays with you. The other is useless on its own — that's the only one we hold.
On your device
- Your private key — created here, never sent to YourID
- Your face, fingerprint or PIN — checked by your device itself
- Optional: your platform's passkey sync (iCloud Keychain, Google Password Manager)
At YourID
- Your public key — it can check a signature, never make one
- Your email address, for codes
- Profile fields you fill in, each marked private, on request or public
- Which services you've connected, and what each may see
- Your activity log of sign-ins and consents
At the service
Only what you approved
- Only the items you allowed
- For an age check: “over 18” — yes or no
- Nothing at all after you revoke, from then on
Delete your account and your data is removed from YourID's live database immediately. What a service already received is governed by that service's own policy.
The consent screen
Every part of the screen has a job.
This is what you see before any service gets anything. Tap a label to see where it is.
What a service can ask for
Name
Your name
Date of birth
Asked for separately from your name
Email
Your email address
Age check
Only yes or no: over 18
Personal profile
Fields you fill in yourself
Business profile
Fields you fill in yourself
Medical and financial drawers
Not in the beta
Every profile field has a visibility
- Private
- Never offered to any service.
- On request
- Can appear on a consent screen — shared only if you allow it.
- Public
- Can appear on a consent screen — shared only if you allow it.
For the technically curious
Passkeys
WebAuthn / FIDO2 — phishing-resistant by design, and no shared secret on our side.
OpenID Connect + PKCE
The authorization code flow, the open standard services already know how to use.
Derived claims
age_over_18 answers the question without handing over the birthdate.
Signed tokens
RS256 signatures with a published JWKS, so services can verify every token.
Lost your phone?
Losing a device doesn't mean losing your identity.
What happens next depends on where your passkey lived.
Your passkey was synced
Nothing to doIf you saved it in your platform's passkey sync — iCloud Keychain or Google Password Manager — it comes back on your new phone automatically once you sign in to that account.
Your passkey was only on that phone
Three steps- 1
Sign in with an email code
On any other device, ask for a code. It's valid for 10 minutes.
- 2
Add a new passkey
Create one on the device you're using now.
- 3
Remove the lost one
In Settings, delete the lost phone's passkey so it can never be used again.
Worried someone else is signed in? You can also sign out your other devices.
Verified identity
Later, you'll be able to prove your name and age from your ID document, through our verification partner iDenfy (EU). It isn't available in the beta yet.
- Your document is checked by the verification partner — YourID doesn't store it.
- Services then receive a verified claim, such as a confirmed name or “over 18”, instead of a copy of your ID.
Try it yourself.
We're letting people into the private beta week by week. Leave your email and we'll send an invitation.