Veyns ID Sandbox

Security

Protocol

OpenID Connect Authorization Code with PKCE (S256) only, following the OAuth 2.0 Security BCP (RFC 9700): exact redirect URI matching, single-use short-lived codes, rotating refresh tokens with family revocation on reuse, and token revocation.

Authentication and approval

Browser sign-in requires a registered device credential and a verified signature. Palm sign-in uses a scanner linked to the same account. Application approvals bind the application, intended user, exact action and expiry. A request cancelled during verification cannot later be approved.

Keys and delivery

Applications validate signed tokens with our published verification keys. Client secrets stay on application servers. Security state and acknowledgement records survive service restarts in encrypted transactional storage. Repeated delivery can be reconciled; the application must deduplicate its own business operation.

Sandbox scope

Palm access is restricted to admitted pilot accounts and applications. This sandbox does not establish hardware-signed capture freshness, certified attack detection, isolation for unrelated customer organizations or a production availability commitment. The registered Android capture software remains part of the trusted system.

Reporting

Report a security issue to info@veyns.io.