Digi-ID lets you sign in to a website, app, or location using a QR code. The service must support Digi-ID before you can use it there. It uses cryptography, the same type of mathematics used to secure DigiByte, to verify your sign-in. Digi-ID can replace a username and password or be used alongside them.
Why use Digi-ID?
When Digi-ID replaces your password, it removes several common password risks:
- No password to remember, write down, or share.
- No sign-in password for the website to store or an attacker to steal or guess.
- No password reuse across accounts.
- No password to capture with keystroke-recording software.
How does sign-in work?
- The service displays a unique QR code for your sign-in request. It includes a one-time value and tells your Digi-ID app where to send its response.
- Scan or tap the code and confirm the request in your Digi-ID app.
- The app uses your private key to create a digital signature, then sends the signed response and your public login address to the service. This uses very little data.
- The service verifies the signature and login address, then signs you in.
Why don’t I need a username or password?
Your public login address identifies you to the service, while the digital signature proves you control the matching private key.
Could someone guess my login?
Digi-ID uses cryptographic keys instead of passwords. These keys are designed to make guessing impractical.
Is signing in on a shared computer safe?
Digi-ID avoids typing a website password on that computer. It does not make the computer safe; an attacker could still capture the active session or data shown in the browser. Users should sign out when finished.
Could someone trick me into signing them in?
Yes. If you approve a code presented by someone else, they may gain the session.
Only approve Digi-ID codes on pages you opened yourself. Be careful with codes sent in messages, shown by another person, or reached through an unexpected link.
What if I lose my phone?
If you backed up your recovery phrase, you can restore your Digi-ID identity in a compatible app on another device.
Recovery options depend on the app; if remote erase is available on the lost device, use it. Check for compatible software for Android, iOS, PC, or Mac.
If you lose the recovery phrase as well, that Digi-ID identity cannot be restored. Keep the recovery phrase somewhere safe and offline.
There is no password reset and no support team holding a copy. Individual websites may still let you prove who you are another way and set up a new Digi-ID identity for your account, so it is worth asking them.
Can I use Digi-ID on more than one device?
Yes. You can use the same Digi-ID identity on multiple compatible devices or a separate identity on each device.
To use the same identity on another device, restore it there from the same recovery phrase. Setting up a device with a new recovery phrase creates a separate identity, and websites will treat it as a different user.
Can a website see my DigiByte balance?
No. Digi-ID uses a login address separate from your DigiByte wallet address and generates a different login address for each website.
Do not send DigiByte to a Digi-ID login address. Funds sent there will not appear in your wallet.
What personal information does Digi-ID share?
Digi-ID does not need your name, date of birth, or phone details to sign you in. The app sends your public login address and a signed response.
Each sign-in request includes a “nonce,” an unpredictable value that identifies a specific request (for example, x=458c552d84a8a347). The request does not include your name or any other personal details.
Questions? Contact us.
Account support: For account-specific problems, see the website or service provider where you are attempting to sign in.
No DigiByte channel can help with an individual website’s Digi-ID account.
General questions: If you have any questions about this documentation or wish to communicate with DigiByte community support, reach out to @DigiAwareness_ with requests.
Ready to try Digi-ID? Get started