Passkey authentication
WebAuthn with device-bound private keys. Biometric checks happen on your device, never on our servers. No passwords to steal.
RocketID separates lookup, authentication, and purchase authorization into distinct security boundaries. Each step requires independent verification.
WebAuthn with device-bound private keys. Biometric checks happen on your device, never on our servers. No passwords to steal.
Address, phone, and identity fields are encrypted at rest. Lookup flows use hashes and challenge-based verification — profile data is never exposed on email entry.
Before purchase completion, RocketID issues a short-lived authorization token after the shopper confirms with their device biometric again.
Merchants only receive what they need — shipping address and verification status. RocketID never shares raw card data or browsing behavior.
Checks if an email has a RocketID. Returns available auth methods — no profile data.
Passkey or OTP challenge. Issues a scoped session token on success.
Session token grants access to read/write identity, addresses, and payment refs.
Second biometric confirmation before checkout finalization. Issues a one-time authorization token.
Identity is tied to the device holding the private key, not to a password a hacker can guess.
Profile data is only released after a successful passkey or OTP challenge — never on lookup alone.
Each API call is scoped. Session tokens are short-lived. There is no persistent login cookie.
Account data, passkeys, and connected store history can be permanently deleted from the dashboard.
Create a RocketID and experience passkey-first checkout identity.