Knowledge Base
Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.
Tagged: authentication
9
Accounts
API Keys for Programmatic Access
Long-lived Truestamp API keys presented as Authorization Bearer credentials to authenticate the JSON:API, GraphQL, and console surfaces, how a key is created, revoked, and audited, and how they differ from OAuth 2.1 used by the MCP surface.
Passkeys
How Truestamp passkeys work - phishing-resistant WebAuthn sign-in with Touch ID, Face ID, Windows Hello, or a security key that replaces your password, added and managed from your profile, and completing sign-in in one step with no two-factor TOTP code.
Signing In to Truestamp
How you authenticate to Truestamp - password sign-in throttled against brute force, passwordless magic-link sign-in, one-step passkey sign-in, an optional TOTP second factor with throttled recovery codes, the limits on account emails, and how a session is established and ended.
The Life of a Truestamp Account
What happens to an account from sign-up through email confirmation, the one-time immutable username claim, the personal team every user gets, the two system roles, and cascading account deletion.
Two-Factor Authentication and Recovery Codes
How Truestamp two-factor authentication works - authenticator-app (TOTP) enrollment and verification, single-use recovery codes, and the per-account brute-force rate limits on TOTP and recovery-code entry.
Glossary
API key
A long-lived opaque credential (prefix truestamp_) that authenticates programmatic requests as your whole account, sent as an Authorization Bearer header on JSON:API and GraphQL or as a connection parameter on the console WebSocket; the MCP surface never accepts one and requires OAuth 2.1.
Magic link
A single-use, time-limited sign-in link Truestamp emails to your address as a passwordless alternative to password sign-in; if no account exists for that email one is created on the spot, and an enabled TOTP second factor still applies after the link signs you in.
Passkey
A phishing-resistant WebAuthn sign-in credential on a Truestamp account, approved with Touch ID, Face ID, Windows Hello, or a security key, completing sign-in in one usernameless step that skips the TOTP prompt; added, renamed, and removed from the profile page.
TOTP
Time-based One-Time Password, the optional authenticator-app second factor on a Truestamp account; after a password or magic-link sign-in you enter the app's rotating six-digit code, with code entry rate-limited to 3 attempts per 5-minute window against brute-force guessing.