
§01 Identity & Access
Account Recovery Without a Back Door: Secure With the Narrowest Path
When account holders lose the things that authenticate them, the path to recovery is a security control, not a support convenience. Brute-forcing it…
Identity, trust and the plumbing of the web·on the home of the Yadis discovery protocol since 2005
§01 Section
Who you are online and who vouches for it: sign-in protocols, passkeys, delegated access and the machinery behind a digital identity.

§01 Identity & Access
When account holders lose the things that authenticate them, the path to recovery is a security control, not a support convenience. Brute-forcing it…

§01 Identity & Access
Online gaming is not only about games, fun, and bright graphics. It is also about trust. When people play with real money, they share personal data…

§01 Identity & Access
An OpenID Connect ID token is not a user-identity data blob. It's a compact cryptographic artifact that only speaks to authentication when the…

§01 Identity & Access
Designing OAuth scopes is a critical aspect of any modern application that relies on third-party integrations and user permissions. Poorly designed…

§01 Identity & Access
Device-bound passkeys are lost forever if the hardware storing them fails or is stolen. With a synced passkey, the private key is stored online. Once…

§01 Identity & Access
The current version of the Yadis specification is 1.0, released March 2006.
The Yadis wiki is the reason this section exists. Browse the archive →