Knowledge Base
Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.
Tagged: security
19
Accounts
API Keys for Programmatic Access
Long-lived Truestamp API keys presented as Authorization Bearer credentials to authenticate the JSON:API, GraphQL, and console surfaces, how a key is created, revoked, and audited, and how they differ from OAuth 2.1 used by the MCP surface.
Passkeys
How Truestamp passkeys work - phishing-resistant WebAuthn sign-in with Touch ID, Face ID, Windows Hello, or a security key that replaces your password, added and managed from your profile, and completing sign-in in one step with no two-factor TOTP code.
Signing In to Truestamp
How you authenticate to Truestamp - password sign-in throttled against brute force, passwordless magic-link sign-in, one-step passkey sign-in, an optional TOTP second factor with throttled recovery codes, the limits on account emails, and how a session is established and ended.
The Life of a Truestamp Account
What happens to an account from sign-up through email confirmation, the one-time immutable username claim, the personal team every user gets, the two system roles, and cascading account deletion.
Two-Factor Authentication and Recovery Codes
How Truestamp two-factor authentication works - authenticator-app (TOTP) enrollment and verification, single-use recovery codes, and the per-account brute-force rate limits on TOTP and recovery-code entry.
Cryptography
Domain-Separated Hashing (SHA-256 Byte Prefixes)
How Truestamp separates SHA-256 hash contexts with single-byte domain prefixes, keeping leaf hashes, node hashes, and each kind of hashed object in distinct hash spaces to prevent ambiguity and second-preimage confusion.
Ed25519 Signatures
How Truestamp uses Ed25519 to sign the domain-separated hashes of items, blocks, entropy observations, and proof bundles, what a signature proves to a verifier, how to fetch and pin the public keyring from /.well-known/keyring.json, and how a bundle can carry the key event that introduced its key.
Glossary
API key
A long-lived opaque credential (prefix truestamp_) that authenticates programmatic requests as your whole account, sent as an Authorization Bearer header on JSON:API and GraphQL or as a connection parameter on the console WebSocket; the MCP surface never accepts one and requires OAuth 2.1.
OAuth 2.1
Truestamp's built-in authorization server (authorize, token, register, revoke endpoints with RFC 8414/9728 discovery) issuing audience-bound access tokens and rotating refresh tokens via PKCE S256 consent, with per-surface mcp/api/console read and write scopes; the only credential MCP accepts.
Passkey
A phishing-resistant WebAuthn sign-in credential on a Truestamp account, approved with Touch ID, Face ID, Windows Hello, or a security key, completing sign-in in one usernameless step that skips the TOTP prompt; added, renamed, and removed from the profile page.
Public randomness beacon
A service that periodically publishes unpredictable, bias-resistant, publicly verifiable random values everyone can observe; Truestamp both consumes external beacons such as the NIST Randomness Beacon as entropy and acts as one itself through the public /beacons page.
Recovery code
A single-use backup code issued in a batch when Truestamp two-factor authentication is enrolled, entered in place of a TOTP code at the second-factor step; each code works exactly once, only a hashed form is stored, and regenerating a batch invalidates the previous one.
TOTP
Time-based One-Time Password, the optional authenticator-app second factor on a Truestamp account; after a password or magic-link sign-in you enter the app's rotating six-digit code, with code entry rate-limited to 3 attempts per 5-minute window against brute-force guessing.
Webhook (outgoing)
An HTTPS endpoint registered with Truestamp to receive outgoing item event callbacks, managed over the JSON:API and GraphQL surfaces, with optional bearer-token authentication, delivery tracking, private-IP SSRF safeguards, no HMAC payload signing, and a per-plan endpoint limit.