Help
Using Identizen
Answers for people who use the app. Developers integrating Identizen should read the documentation instead.
Getting started
- How do I get the app?
- The iPhone app is on the App Store; the download page links to it and to the TestFlight beta, which gets new builds first. The Android app is coming to Google Play. Meanwhile the playground at identizen.com/playground lets you try a login with a virtual phone.
- What happens when I create an identity?
- The app generates a secret on your phone and shows it to you once as 24 words. Those words are the only copy. Write them down and keep them somewhere safe. Nobody, including us, can recover them for you.
- Why does the app ask for Face ID or my fingerprint?
- Your identity is locked with it. Each time you approve a sign-in, the phone asks for your biometric and then signs the request. Without it, nothing signs. If your phone has no biometric, the device passcode is used instead.
- What is the dashboard?
- app.identizen.com shows the devices, browsers, and sessions that belong to your identity, and lets you revoke any of them. You sign in to it the same way as any other site: with your phone.
Signing in
- How do I sign in to a website?
- Click the site’s Continue with Identizen button. The first time from a computer, it shows a QR code and a two-digit code. Open the app, scan the QR, check that the app shows the same site name and the same two digits, and approve with your biometric. The site signs you in.
- What is the two-digit code for?
- It proves the request on your phone is the one on your screen. If the digits differ, someone else started that request. Deny it.
- Why did my second login skip the QR code?
- After your first approval, that browser is paired with your phone. Later sign-ins from it go straight to your phone as a notification. You can see and unpair every browser in the app or the dashboard.
- What is nearby sign-in?
- On a computer with Bluetooth, a site can find your phone without a QR code when you click the option. Your phone broadcasts an identifier that changes every 15 minutes and only the Identizen index can resolve. You can turn this off in Settings.
- Signing in on the phone itself?
- Tap Continue with Identizen on the site and then Open in Identizen. The approval happens in the app, and the site finishes signing you in when you return to the browser.
- A request arrived that I did not start.
- Deny it. Nothing happens to a denied request, and the site never sees anything. If it keeps happening, revoke the paired browser it came from in the Browsers tab.
Approving actions
- A site asked me to approve a transfer or another action. What am I signing?
- Exactly the text on your screen. The site’s server wrote it, your phone shows it, and your approval is bound to that text. If the amount, the payee, or the action is not what you expected, deny it.
New phones and lost phones
- I have a new phone.
- Install the app, choose Restore, and enter your 24 words. Your identity is identical on the new phone, and every site recognizes you. Then revoke the old phone from the Devices tab or the dashboard.
- I lost my phone.
- Sign in to app.identizen.com from another device, or use another phone that holds your identity, and revoke the lost phone. It is signed out of every site immediately and can no longer approve anything. A locked phone cannot sign without your biometric or passcode in the meantime.
- I lost my phone and my 24 words.
- The identity cannot be recovered. Create a new one on your new phone. Sites that knew the old identity will treat you as a new person; contact each site and go through its own verification to link your new identity to your existing account there.
- Can I use two phones?
- Yes. Restore the same 24 words on the second phone. Both phones hold the same identity and either can be revoked from the other.
Privacy and your data
- What does a website learn about me?
- An identifier that is unique to that site, and nothing else. No email, name, or phone number, and no identifier another site could match. If a site needs those, it asks you directly.
- What is a handle?
- An optional public name, like @jordan, that you can set in Settings. Sites that ask for it receive it once you have set one. Leave it empty to stay anonymous everywhere.
- What does Identizen store?
- Public keys, a token to send notifications, the identifiers each site knows you by, and a record of approvals and revocations. Never your secret, your 24 words, or anything that could sign in as you. The privacy policy has the full list.
- How do I delete everything?
- Forget the identity in the app’s Settings, revoke the phone from the dashboard, and ask us to delete the remaining records. The steps are on the delete page.
Still stuck? Contact us. Building a site? Read the documentation.