Trust the evidence.
Know its limits.
I’m Real binds a verification result to an application and protected action. The backend evaluates the evidence; browsers, widgets and coding agents cannot declare a production verification successful.
Enrollment and authentication are different
Enrollment establishes accepted human-presence evidence through a provider. A passkey later authenticates control of a credential linked to that enrollment. It cannot establish that the credential controller is biologically human, that a biometric unlocked the authenticator, or that every subsequent action was performed manually.
Transaction protections
- WebAuthn signatures, RP ID, origin, challenge and user verification are checked by SimpleWebAuthn.
- Challenges and authorization codes expire and are consumed once.
- S256 PKCE, state, nonce, browser binding and exact redirect registration protect the transaction.
- Assertions use ES256, with issuer, application, action, environment and expiry checks.
- The integrating backend must consume each verification ID with its protected action.
Tenant and agent boundaries
Partner credentials are limited to their customer hierarchy. Applications receive pairwise pseudonyms. MCP uses OAuth with tenant membership and scope validation; production mutations and secret creation cannot be authorized by a tool argument.
Residual risks
Human-assisted fraud, stolen or shared passkeys, provider compromise, synthetic biometric injection and compromised customer applications remain material risks. A provider must be independently evaluated and the deployment reviewed before production use. Global uniqueness is not claimed.
Deployment status
This product is under active development. Sandbox testing, automated checks and a production-readiness checklist are included in the repository. They are not an independent audit, certification or guarantee of universal accessibility.