UNIKEY DEMO APPLICATION

The Missing Authority Layer, at work

The internet was built to move information. It was never built to prove authority. This demo shows UniKey checking that each action, whether a payment, a bank change or an order, was explicitly authorized before it executes.

They verify the agent. UniKey verifies the action.

POST /banking/api/v1/payments
# Trust Packet, signed on the sender's device
{
  "action":   "submit_payment",
  "subject":  "ap.clerk@acme-corp.com",
  "signer":   "acme-corp.com",
  "params":   { "payee_id": "PAY-20418", "amount": "12,480.00" },
  "signature": "ed25519:9f3c…a71e"
}

# Verified against the key acme-corp.com publishes in DNS
✓ signature  ✓ not replayed  ✓ within scope
→ payment executes, certificate recorded

THE PROBLEM

Identity Is Not Authorization

Every credential, password, token and session is a patch on the internet's original omission. A stolen credential passes identity checks designed to verify who is acting, not whether the action is authorized.

"Was this action explicitly authorized, before it executed?"

$28B

Card-not-present fraud projected for 2026

$23B

Account takeover fraud, US 2023

97%

of organizations saw AI-facilitated attacks rise in 2025

Figures as cited on unikeyid.com.

HOW IT WORKS

Send. Verify. Act.

UniKey sits between identity and execution. Every action carries its own proof of authority, checked in milliseconds before anything happens.

  1. 01

    Send

    The person, device or agent signs a Trust Packet for one specific action, with a key that never leaves the device.

  2. 02

    Verify

    The receiving service checks the signature against the signer's key in DNS, rejects replays and confirms the action is within scope.

  3. 03

    Act

    Only a verified action executes. Anything ambiguous is refused, and the outcome is kept as a tamper-evident certificate.

FOUR CRYPTOGRAPHIC PRIMITIVES, ONE AUTHORITY LAYER

Authority Anchors

Who holds the authority to act: a person, device or system with a domain-based key.

Trust Packets

Per-action proofs: signed, self-contained and non-replayable.

Authorization Certificates

Hash-chained records of multi-party sequences. Change one step and the chain breaks.

Authorization Ledgers

Append-only records each party keeps and can verify independently.

INSIDE THE DEMO

Real apps, talking over HTTPS, trusting nothing but proof

UDA runs separate applications that call each other the way independent companies would. Every write that matters carries a Trust Packet, and every refusal shows you why. The recordings show it at work.

UDA ERP

A storefront, sales and procure-to-pay, where a supplier's bank change is held until it is verified.

UDA Banking

Pays suppliers for UDA clients, keeping a trust log of every packet it verified or refused.

UDA Hospital

Patient records and billing, the next app to gain signed actions.

GET STARTED

Sending is free. Verification is where value is exchanged.

Watch the recorded demos, or talk to the team about a live walkthrough, founding partner status and licensing.