Security
Protocol
OpenID Connect Authorization Code with PKCE (S256) only, following the OAuth 2.0 Security BCP (RFC 9700): exact redirect URI matching, single-use short-lived codes, rotating refresh tokens with family revocation on reuse, and token revocation.
Authentication and approval
Browser sign-in requires a registered device credential and a verified signature. Palm sign-in uses a scanner linked to the same account. Application approvals bind the application, intended user, exact action and expiry. A request cancelled during verification cannot later be approved.
Keys and delivery
Applications validate signed tokens with our published verification keys. Client secrets stay on application servers. Security state and acknowledgement records survive service restarts in encrypted transactional storage. Repeated delivery can be reconciled; the application must deduplicate its own business operation.
Sandbox scope
Palm access is restricted to admitted pilot accounts and applications. This sandbox does not establish hardware-signed capture freshness, certified attack detection, isolation for unrelated customer organizations or a production availability commitment. The registered Android capture software remains part of the trusted system.
Reporting
Report a security issue to info@veyns.io.