Security
Built so there's little to steal.
Every statement on this page describes how YourID actually works today — including what isn't finished yet.
Last updated: 1 October 2026
- passwords stored
- 0passwords stored
- lifetime of an email code
- 10 minlifetime of an email code
- lifetime of a sign-in code for a service
- 60 slifetime of a sign-in code for a service
- longest a service stays connected on one sign-in
- 30 dayslongest a service stays connected on one sign-in
How a sign-in travels
Your secret stays home. Only proof travels.
When a service asks “who is this?”, three parties take part. Watch what moves between them — and what never does.
Your device
Never leaves
- Private key of your passkey
- Face, fingerprint or device PIN
YourID
- Public key only
- Email codes, hashed
- Signing key, encrypted
- Database in the EU (Ireland)
The service
shop.example
- Only the claims you approved
- Signed by YourID
Data
What we keep. What we never have.
The safest data is data we don't hold. Here is the full picture of what sits in our database.
What we store
Your email address
To find your account and send sign-in codes.
Your passkeys' public keys
They can check a signature, but can't make one.
Email sign-in codes — as hashes
Valid for 10 minutes; we can check a code, not read it back.
Refresh tokens and app secrets — as hashes
Useless to anyone who copies the database.
Which services you connected
And exactly what you allowed each one to see.
Sign-in sessions and an activity log
Including browser and IP address, so you can see them and sign out anywhere.
Profile details you choose to add
Nothing is shared unless you approve it.
What we never store
Passwords
There aren't any. Nothing to guess, reuse or leak.
Your passkey's private key
It stays on your device or in your platform's own passkey sync.
Your face or fingerprint
Your device checks those itself. We only learn that the check passed.
Readable sign-in codes or tokens
Only their SHA-256 hashes.
The signing key in plain form
It is stored encrypted with AES-256-GCM.
Identity documents
Document verification isn't live yet, so no document is processed at all.
Protections
Twelve things doing the work.
Each one in plain words — with the technical name underneath, for developers who want to check.
No passwords
You sign in with a passkey, so there is no password to phish, guess or reuse.
WebAuthn / FIDO2 passkeys
It has to be you
Every passkey sign-in requires your face, fingerprint or device PIN, and our server checks that it happened.
User verification (UV) enforced server-side
Challenges work once
Each sign-in challenge can be used a single time and expires after five minutes.
Single-use WebAuthn challenges · 5-min TTL
Email codes, contained
Codes are stored hashed, expire in 10 minutes, allow 5 tries, and requesting a new one retires the old.
SHA-256 · timing-safe compare · per-IP and per-address rate limits
Sessions you can end
Your session is a signed token backed by a server record, lasts at most 7 days, and you can sign out everywhere.
Signed HttpOnly cookie + revocable session row
Standard sign-in for services
Services connect through the open standard, and every request must be locked with a one-time proof.
OpenID Connect · authorization code flow · PKCE S256 required
Exact return addresses
We only send you back to an address the service registered in advance, character for character.
Exact redirect-URI match · https only (localhost excepted)
Sign-in codes expire fast
The code a service redeems works once, within 60 seconds. A second attempt revokes what was issued.
Single-use auth codes · 60 s TTL · replay revokes tokens
Answers are signed
Services can verify that an answer came from YourID and wasn't changed on the way.
RS256-signed ID tokens · published JWKS
Long-lived access, renewed safely
Each renewal swaps the token for a new one; if an old one is reused, the whole chain is cancelled. Thirty days at most.
Refresh-token rotation · reuse detection · fixed 30-day family lifetime
Consent counts right now
A service only gets what you currently allow. Withdraw consent and its existing tokens stop working.
Effective scope = token scope ∩ current consent
Keys locked, database closed
Our signing key is encrypted, app secrets are hashed, and the EU database only answers our own servers.
AES-256-GCM · hashed client secrets · RLS on every table, no policies
Threats
Attacks, and what stops them.
No system is unbreakable. These are the attacks we designed against, and the specific mechanism that answers each one.
The attack
Phishing
A fake site that looks exactly like YourID asks you to sign in.
What stops it
A passkey is bound to YourID's real domain. Your device won't use it on a look-alike, and our server rejects signatures made for any other origin.
WebAuthn RP ID + origin binding
The attack
A stolen database
Someone gets a full copy of our data.
What stops it
There are no passwords to crack. Public keys can't sign anyone in, and codes, tokens and secrets are only stored as hashes.
Public-key credentials · SHA-256 hashes · encrypted signing key
The attack
A stolen refresh token
An attacker copies the token a service uses to stay connected.
What stops it
Tokens rotate on every use. When an old one shows up again, the entire family is revoked — and none lives beyond 30 days.
Rotation + reuse detection
The attack
An intercepted code
Someone grabs the one-time code on its way back to the service.
What stops it
Without the secret proof the real service holds, the code is worthless. It expires in 60 seconds and works only once.
PKCE S256 · single-use 60 s codes
The attack
A fake “bank” app
A malicious app registers itself with a trustworthy-sounding name.
What stops it
The consent screen always shows the website you'll be sent to, and apps registered by outside developers carry an “Unverified app” label.
Destination host shown · unverified badge · exact redirect URIs
The attack
Clickjacking
Another site hides our consent screen in an invisible frame to trick your click.
What stops it
No YourID page can be shown inside another website.
CSP frame-ancestors 'none' · X-Frame-Options: DENY · HSTS
The attack
Guessing an email code
A script tries code after code.
What stops it
Five attempts per code, ten minutes to use it, and limits per network address and per email address.
Attempt counter · DB-backed rate limits (fail closed)
Honest status
Where we are today.
Security pages usually only list strengths. Here is what you should also know.
YourID is in private beta
We're admitting people gradually and still changing things.
No independent audit yet
There has not yet been an external security audit or penetration test. We intend to commission one before YourID becomes generally available.
Document verification isn't live
We can't check identity documents yet. Until we can, no document is processed.
Responsible disclosure
Found something? Tell us.
If you find a vulnerability, email us. Good-faith research is welcome here.
- We acknowledge reports within 48 hours.
- We will not take legal action against good-faith research.
Try it for yourself.
Join the beta, sign in with a passkey, and see on your own screen what a service gets to see.