☥ ANKH

Documentation

ANKH is a passkey-first identity provider built on WebAuthn/FIDO and OpenID Connect. This guide describes the stable public integration surface without exposing private operational material.

Authentication

Canonical endpoints

Issuer: https://ankhy.app
Discovery: https://ankhy.app/.well-known/openid-configuration
JWKS: https://ankhy.app/oauth/jwks
Authorization: https://ankhy.app/oauth/authorize
Token: https://ankhy.app/oauth/token
UserInfo: https://ankhy.app/oauth/userinfo
Revocation: https://ankhy.app/oauth/revoke

Security model

Private WebAuthn keys never leave the authenticator. Client secrets and session/refresh tokens are stored server-side only as hashes when plaintext recovery is unnecessary. Recovery is threshold-based and cannot silently downgrade ordinary passkey authentication.

Security overview · Privacy