[PASSKEY-IAM] · BIOMETRIC SUITE

Auths Developer IAM

Passwordless Biometric Presentation Authentication for Infrastructure

Replace static SSH keys, static tokens, and password databases. Authenticate infrastructure access via hardware Touch ID presentation challenges verifiable offline without central identity issuers.

[INTERACTIVE PROTOCOL FLOW]

Zero-Trust Developer IAM Flow

01
1. Infrastructure Request
ssh / kubectl / aws
Requested
02
2. Auths-Presentation Challenge
Explicit Nonce & Audience
Challenged
03
3. Touch ID Biometric Prompt
Secure Enclave Sign
Biometric Pass
04
4. Scoped Session Access
Issuerless KERI Verify
Session Granted
1. Infrastructure Request — Detail

Developer attempts SSH connection, kubectl command, or AWS CLI call.

PASSKEY & PAM · ZERO STATIC SECRETS

Ephemeral Touch ID Presentations for SSH & Kubernetes

Eliminate static SSH private keys like .ssh/id_rsa and long-lived AWS IAM secret keys. Developers authenticate terminal access via Touch ID.

Linux/macOS PAM Integration kubectl Credential Plugin Issuerless Presentations
ZERO_TRUST_AUTH_FLOWZero-Trust Access
01Developer initiates SSH or kubectl access
02Local daemon prompts Touch ID
03Presentation challenge issued to device
04Infrastructure verifies proof & opens session
[CONFIGURATION & INTEGRATION]

Passwordless Infrastructure Authentication

Biometrically backed presentation authentication for SSH terminals, Kubernetes clusters, and AWS CLI credentials.

~/.ssh/config (Passwordless SSH with Auths Presentation)
Host production-bastion.internal
  User dev-alice
  IdentityFile none
  # Auths presentation challenge provider
  ProxyCommand auths rp ssh-challenge --host %h --port %p
[BIOMETRIC-TOUCH]

Hardware Touch ID / Passkey

Replaces static SSH keys and database passwords with Touch ID, Windows Hello, or YubiKey authentication.

[ISSUERLESS-KERI]

Issuerless Presentations

Relying party servers verify developer presentation tokens completely offline without contacting identity providers.

[PAM-MODULE]

Native Linux & macOS PAM

C-FFI pam_auths.so module plugs directly into standard OpenSSH sshd and PAM authentication stacks.

[EXPLICIT-NONCE]

Replay-Proof Nonces

Single-use cryptographic nonces prevent replay attacks across infrastructure management endpoints.