☥ ANKH
Documentation
ANKH is a passkey-first identity provider built on WebAuthn/FIDO and OpenID Connect. This guide describes the stable public integration surface without exposing private operational material.
Authentication
- Passkey-first WebAuthn with user verification required.
- OIDC Authorization Code with mandatory PKCE S256.
- Discoverable credentials and account-managed passkeys.
- Short-lived signed tokens and rotating refresh-token families.
Canonical endpoints
Issuer: https://ankhy.app Discovery: https://ankhy.app/.well-known/openid-configuration JWKS: https://ankhy.app/oauth/jwks Authorization: https://ankhy.app/oauth/authorize Token: https://ankhy.app/oauth/token UserInfo: https://ankhy.app/oauth/userinfo Revocation: https://ankhy.app/oauth/revoke
Security model
Private WebAuthn keys never leave the authenticator. Client secrets and session/refresh tokens are stored server-side only as hashes when plaintext recovery is unnecessary. Recovery is threshold-based and cannot silently downgrade ordinary passkey authentication.