DE:SIGN · WebAuthn Authentication
Passwordless sign-in and task approval — no OTPs, no shared secrets.
DE:SIGN is a WebAuthn-first authentication and task-signing service. Users register a biometric or hardware security key once; every subsequent sign-in and critical-task approval is a cryptographic ceremony — no passwords, no OTPs, no shared secrets on the wire. Device management, task queues, and real-time approval notifications are all handled server-side.
- Auth method
- WebAuthn / FIDO2
- Part of
- Decent Edge product family
What it includes
- Phishing-resistant WebAuthn — Touch ID, Face ID, YubiKey
- Device management: register, name, and revoke multiple devices
- Task approval workflow with inline confirm/reject and real-time push
- Go + HTMX backend; WebAssembly for the WebAuthn browser API
- gRPC API for integration with DE:SH, DE:PLOY, and partner dashboards
Passwordless authentication and task signing
- Okta, Auth0
- Identity platforms with WebAuthn support and broad protocol coverage.
- Duo Security
- Strong MFA with hardware key support, primarily as a second factor.
- Hanko, Passage by 1Password
- Passwordless-first developer libraries, SaaS-hosted.
Those platforms are identity providers. DE:SIGN is a signing service — the WebAuthn credential is also used to approve infrastructure operations, not just authenticate the session. It integrates directly with DE:SH's dashboard and DE:PLOY's task queue so an operator approval is cryptographically bound to the action it authorises.