Skip to content

Trust model

What a binding proves is the short version. This page lists each party, from the specification.

PartyTrusted forIf it misbehaves
The userchoosing the account and approving the bindingnothing beyond their own account
The apprunning the sign-in flow and its configurationcan refuse to work, but cannot change the account, the wallet, or the proof’s time limits
The platform (GitHub, X, Google)saying who owns an accountcan bind any account on that platform
The notary (GitHub, X)signing true records of the user’s sessionscan bind any GitHub or X account
Google’s signing keyssigning true sign-in tokensa stolen key can bind any Google account
The proof verifier and platform verifierschecking proofs correctlya faulty one accepts false bindings for every platform it covers
The contract ownerschoosing verifiers and keys, and upgradingcan change every rule, and so bind any account
The chainordering transactions and reporting timethe usual risks of the chain
  • A proof names one holder and one operation, and the holder must send it itself. A stolen proof cannot bind a different address.
  • Each proof can be used once, and an older proof cannot replace a newer one.
  • Replacing a verifier or a key stops new bindings made with it. It does not undo bindings already written.

The specification lists what it does not defend against: a user misreading a platform’s consent screen, a compromised browser or build of the sign-in flow, and several parties colluding. See Enforceable guarantees.