Whisp3r Auth · Universal identity

Sign in once. Stay yourself everywhere.

Whisp3r Auth is the one account that's actually yours. Your real email stays home, your profile follows you, and any app you stop trusting loses you the moment you say so.

email addresses handed to apps — mail reaches you, your address stays home
0
you. One profile, current everywhere you’ve connected
1
age, proven without a birthday changing hands
13–21
open standard — no walled garden, nothing to rip out later
OIDC

Your email is yours.

Every signup used to cost you something — your address, your inbox, a little more of your attention sold on. Here, apps write to you through an authenticated relay: their message arrives, your address never leaves. Disconnect an app and it isn’t just blocked — it has nothing left to remember you by.

One profile. Every app.

You are not forty profiles drifting out of date. Change your name, photo, or pronouns once and every app you’ve connected sees the current you, instantly. There are no stale copies to chase down, because nothing was ever copied.

Standards, not lock-in.

Whisp3r Auth is plain OpenID Connect — the protocol you already know from Google and Apple, minus the surveillance economics. Point any compliant library at the discovery document and your first sign-in works this afternoon. No proprietary SDK. No per-login pricing. Nothing to rip out later.

// GET https://auth.whisp3r.com/.well-known/openid-configuration
{
  "authorization_endpoint":  ".../oauth2/authorize",
  "token_endpoint":          ".../oauth2/token",
  "response_types_supported":     [ "code" ],
  "subject_types_supported":      [ "pairwise" ],
  "id_token_signing_alg_values_supported": [ "EdDSA" ]
}

Read the docs

You’ve clicked “Agree” on a hundred screens built to be skimmed. This one is built to be read: every field an app wants is listed, the optional ones are switches you flip, the sensitive ones are called out, and the app’s promise about what happens to your data when you leave sits right there — before you say yes. You see it once, and never again unless the app asks for more.

Create your account

One account, owned by you, welcome everywhere. Free for individuals, standard for developers.

Everything else, already built in

  • Passkeys included

    Your face or your fingerprint is the password. Nothing to remember, nothing to leak, nothing for a phishing page to steal.

  • Magic links

    Tap the link in your inbox and you’re in. If typing a password feels safer to you, links switch off in one setting.

  • Two-factor auth

    TOTP guards the account that guards everything else — and apps that need certainty can ask for a verified 2FA session before letting you in.

  • Connection control

    One dashboard lists everyone you’ve let in. Revoke an app and its key dies with the current token — fifteen minutes, at most.

Questions people ask

What do apps actually see?

Only the fields you approved on the consent screen — nothing rides along. And each app knows you by its own anonymous ID, so two apps can’t put their records together and discover they share you.

What happens when I disconnect an app?

You choose the ending: the app deletes your data, archives it, or keeps only what the law makes it keep. Your decision is delivered to the app, and the relay closes the door behind you.

Will I see the consent screen on every sign-in?

Once per app. The only thing that brings the screen back is an app asking for more than you originally agreed to — and then only about the new part.

Is it free?

Free for individuals, with no tier that sells your attention back to you. Developers integrate standard OpenID Connect — no proprietary SDK, nothing to license.

Ready to take your identity with you?

One account, owned by you, welcome everywhere. Free for individuals, standard for developers.

Create your account

An email address or a passkey is all it takes — and you can leave any time, taking everything with you.

enen-GBesfrdept