At The Lab logoContact

Veyns Identity

A private identity and signed-action service for applications, available as a developer sandbox built around pairwise account identifiers, OpenID Connect, WebAuthn, and post-quantum device-wallet proofs.

Developer sandbox

Sign in without exposing one reusable identity.

Veyns gives each application a separate account identifier. Applications do not receive wallet keys, device identifiers, biometric data, or a general user profile.

The same account can issue a fresh signed approval for an exact action, giving payments, sensitive account changes, and automated workflows an explicit authorization step.

Private application identity

Veyns provides standards-based sign-in while limiting the identity information shared with each connected application.

  • Pairwise account identifier unique to each application
  • No shared profile, wallet key, device identifier, or biometric record
  • OpenID Connect Authorization Code flow with PKCE S256

Signed action approval

An application can request a separate user ceremony for a specific payment, account change, or automated action.

  • Approval bound to a canonical digest of the requested action
  • Fresh user verification for each ceremony
  • Intent and assurance information carried in the resulting token

Device trust and signing

The current ceremony combines a post-quantum device-wallet proof with WebAuthn user verification.

  • ML-DSA-44 wallet signature based on FIPS 204
  • WebAuthn assertion requiring device user verification
  • ES256 by default or ML-DSA-44 for compatible ID-token consumers

Developer integration

The sandbox publishes the endpoints and tools needed to register an application and test the complete protocol surface.

  • OIDC discovery, JWKS, authorization, token, user-info, revocation, and logout endpoints
  • Browser SDK for sign-in and action-approval ceremonies
  • Developer console, registered origins, exact redirect URIs, device management, and recovery

Current boundary

The public environment is intended for developer evaluation and is not presented as a production identity service.

  • File-backed sandbox storage with no formal service-level agreement
  • Open registration and data that may reset between releases
  • Palm/vein hardware assurance is a roadmap integration and is not active in the sandbox
Product environment

A working surface for application integration.

Veyns developer sandbox showing private sign-in and signed action approval
Developer sandboxThe public Veyns environment for evaluating sign-in, action approval, account management, and application integration.
Technical note

Evaluation environment

Production use requires a separately reviewed deployment profile, replicated storage, operating commitments, and security validation for the target application and assurance level.

Project discussion

Define the requirement and deployment boundary.

ATL can scope this area as a focused component, an integration, or part of a complete engineering program.

Contact ATL