Skip to content
AUTH.00

Why auth00

A login proves who.
A seal proves what.

Identity tells you who was at the door. It says nothing about the file that went through it. auth00 is the door. sign.it is the proof behind it — and the proof is the product.

The difference

Two questions, two products.

What each answers, and what it cannot
QuestionAnswered byStill open afterwards
Who is at the door? An identity provider. Every one of them, including us. Which file existed. When. Whether it changed since.
What exactly happened? sign.it — a seal on the exact bytes, anchored on three independent rails. Nothing. That is the point.

Both are needed. A seal without a sender is an orphan, and a sender without a seal is a claim. That is why the identity platform is the way in and not the product.

How it holds

Three properties you can check without us.

The file never moves

SHA-256 is computed in your browser. Sixty-four characters travel; the asset stays on your device. There is no upload to trust and no copy to leak.

Three independent rails

An RFC-3161 time authority, the bitcoin calendars via OpenTimestamps, and an on-chain anchor. One confirmed rail is enough. Three make it hard to argue with.

Checkable if we disappear

The proof is an open format against public anchors. Anyone can verify a file at auth00.co/verify — no account, no upload, no dependency on us still being here.

Where we are ahead

Agents sign in here today.

An agent that acts on its own needs an identity of its own, and an audit trail that survives the conversation it came from. Ours runs in production:

  • Its own credentials. client_credentials with per-app scopes the tenant approves — not a human account the agent borrows.
  • Tokens bound to a key, not to a bearer. DPoP: the minted token carries cnf.jkt, so a stolen token is useless without the private key it was minted against.
  • Keys rotate, and reuse is fatal. A replayed key revokes its whole family, so a leaked credential ends the family instead of quietly living on.
  • Measured, then certified. The AATP test bench measures an agent service against its running behaviour and issues a signed, revocable certificate into a public, recomputable transparency log.

To be exact about the comparison: parts of the large vendors' agent stack are shipping, parts are beta, and parts are announced. Ours is in production — and the revocable measured certificate has no counterpart there at all.

Where we are not

What we do not have yet.

This belongs on this page and not in a footnote. If you are buying infrastructure, you already know that the missing items decide more than the present ones.

  • No ISO 27001, no SOC 2, no FedRAMP. Not "in progress" as a figure of speech — simply not held today. What we do instead is on the trust page, in full, including what it does not replace.
  • No global region picker. We run in Europe. If your procurement needs data residency elsewhere, we are not your answer this year.
  • No twenty-person support desk. You will reach the people who wrote the code, which is faster in the good case and thinner in the bad one.

If any of these is a hard requirement, buy the large vendor. We would rather say that here than in month three of an integration.

Seal your first file with auth00

A proof you can hand over is worth more than a promise you have to repeat. One field, one file, and you have something you can show.