Wallet-Native Authentication live demo
| 1 min read
I’ve now implemented a working demo of the wallet-native authentication protocol for Cardano described in my technical specification . The demo is live and can be tried directly in the browser: Give it a try!
The demo currently covers the complete authentication flow:
- Connect a CIP-30 wallet.
- Sign up with a structured, human-readable message.
- Log in using a fresh server-issued nonce.
- Verify the signature through the complete server-side pipeline:
parse → address → nonce → timestamp → uri → action → signature.
And presents a few extra use cases and failure cases:
- Re-authenticate by proving wallet ownership again.
- Demonstrate replay protection by submitting the exact same signed message twice.
- Demonstrate origin binding by attempting to authenticate with a deliberately forged uri.
Deliverables
Video Tutorials
Source code for the demo
Demo is embedded in this website, yet a self-contained and didactical demo code is available on https://github.com/Titan-C/cardano-web-auth/ .
CIP-93 amendment
Developing the specification for this project and this demo required me to
provided an amendment to CIP-93
. I expect this finally brings that CIP from the
proposed to the active, allowing everyone to benefit from a standardized
wallet authentication specification.
Follow the pull request .