Signing in without a password
Challenge-response: proof of the key, without transmitting it.
Step 2 of 5
The three moves
First, you enter your address and the PIN that unseals this device’s copy of your key. This happens entirely on your device.
Second, the platform issues a one-time challenge — a random string bound to your address that expires in five minutes and can be used exactly once.
Third, your device signs the challenge and the platform verifies the signature against your registered public key. A valid signature is mathematical proof that the private key was present — the key itself never crosses the network.
Why there is no password
Passwords are transmitted secrets: every login sends something that, if intercepted, works forever. A signature proves possession without revealing anything reusable. There is nothing to phish, reuse, or leak.
