For domains

Be your own identity provider — with one DNS record.

browserid.me issues certificates as your domain — your users sign in as you@yourdomain.com everywhere, you govern every identity and agent from one console, and you can leave anytime.

Managed identities

Offboard anyone — and every agent they ever authorized — with one click.

A managed identity answers to its domain: you set the roster, the sites, and what agents may be granted. When someone leaves, one revocation stops their sign-ins and kills every agent grant they ever signed — everywhere, without you having to know where "everywhere" is.

  • Roster: only identities you created (or approved) exist.
  • Constraints ride in the certificates and are enforced by verifiers — not by trust in us.
  • Users see plainly that a managed identity answers to its domain; their personal identities are untouched.
  • Per-tenant keys, sealed and exportable — a compromise is isolated to one domain, and the key is yours to take self-hosted.
How it works

Publish one record. That's the onboarding.

Add a signed _browserid record to your DNSSEC-secured zone and browserid.me operates the full identity surface as your domain — the issuer is you, not us. Relying parties resolve your key straight from DNS; no one calls our servers to trust your users.

And it's never a one-way door. It's your domain and your DNS: issue through us today, and flip that one record to a self-hosted key whenever you want. Nothing you depend on is un-leaveable — no migration, no permission, no lock-in.

yourdomain.com · from setup to exit
1
Add one DNS record
We give you the record; you paste it at your DNS provider. That's the whole setup.
2
Your users just sign in
Every identity is issued as @yourdomain.com — apps see you as the issuer, never us.
Leave whenever you want
Change that same record to a key you hold and you're self-hosted — no migration, no permission needed.
Coming soon roadmap

Directory sync

Point at your Google Workspace and your directory is the roster — users auto-provision on first sign-in and deprovision when you remove them. No roster to maintain by hand.

Coming soon roadmap

Self-host the primary kit

Run the whole primary surface yourself, on your own key, from day one — the same protocol, no custodial step at all.