Mint a session
POST /v1/sessions with your secret key. A session scopes one enrollment or login and names your callback.
hostedUrlAuthenSee authenticates your users with zero-knowledge proofs instead of passwords. Mint a session, hand off to a hosted flow, exchange a one-time code. You integrate it like a payment provider — and store nothing phishable.
app.js$ npm i @rebellion-systems/authensee-embed
import { open }
from '@rebellion-systems/authensee-embed';
open({
flowUrl: async () => {
const res = await fetch('/api/authensee/session',
{ method: 'POST' });
return (await res.json()).hostedUrl;
},
onComplete: ({ authResultCode }) => {
// exchange server-side, get a JWT
fetch('/api/authensee/complete', { … });
},
});The passkey ceremony and proof generation run on AuthenSee's origin, in a popup on the user's device. Your code never touches a secret — it moves session handles and one-time codes.
POST /v1/sessions with your secret key. A session scopes one enrollment or login and names your callback.
hostedUrlThe drop-in opens the hosted flow on AuthenSee’s origin. Passkey ceremony + ZK proof run on-device.
authResultCodeSwap the single-use code for a signed auth result. Verify the EdDSA JWT against the public JWKS.
providerSubject + tokencurl · or @rebellion-systems/authensee-sdk# 1 · a session scopes one login
curl -X POST api.authensee.com/v1/sessions \
-H "x-api-key: sk_live_…" \
-d '{ "scope": "full",
"externalUserId": "user_12345",
"callbackUrl": "…/callback" }'
→ hostedUrl // hand this to the browser# 3 · exchange the one-time code
curl -X POST …/v1/auth-results/exchange \
-H "x-api-key: sk_live_…" \
-d '{ "authResultCode": "ar_bxvS6d…" }'
→ status: "authenticated"
→ providerSubject // stable user id
→ token // EdDSA JWT, verify via JWKSProofs are generated on the user's device — WASM in the browser, native on mobile. Everything past the device boundary is opaque by construction.
Verifies proofs without ever seeing answers, gestures, or keys.
A signed result. No credential to store, leak, or rotate.
Nothing to phish, stuff, or rotate — authentication is a proof of knowledge, not a stored credential.
The AuthenSee server verifies proofs without ever seeing answers, gestures, or keys.
A full database dump reveals only opaque commitments and spent nullifiers — nothing exploitable.
Every proof carries a single-use nullifier; a captured proof can never be reused.
Users reuse the same persona across every AuthenSee-integrated app. No re-onboarding.
passkey_and_image_points, passkey_only, or passkey_and_behavior — switch policy without forcing re-enrollment.
Create a provider, copy your sk_test key, and run the quickstart. Five steps, one dependency, no credential storage.