UNIKEY DEMO APPLICATION
The Missing Authority Layer, at work
The internet was built to move information. It was never built to prove authority. This demo shows UniKey checking that each action, whether a payment, a bank change or an order, was explicitly authorized before it executes.
They verify the agent. UniKey verifies the action.
# Trust Packet, signed on the sender's device { "action": "submit_payment", "subject": "ap.clerk@acme-corp.com", "signer": "acme-corp.com", "params": { "payee_id": "PAY-20418", "amount": "12,480.00" }, "signature": "ed25519:9f3c…a71e" } # Verified against the key acme-corp.com publishes in DNS ✓ signature ✓ not replayed ✓ within scope → payment executes, certificate recorded
THE PROBLEM
Identity Is Not Authorization
Every credential, password, token and session is a patch on the internet's original omission. A stolen credential passes identity checks designed to verify who is acting, not whether the action is authorized.
"Was this action explicitly authorized, before it executed?"
$28B
Card-not-present fraud projected for 2026
$23B
Account takeover fraud, US 2023
97%
of organizations saw AI-facilitated attacks rise in 2025
Figures as cited on unikeyid.com.
HOW IT WORKS
Send. Verify. Act.
UniKey sits between identity and execution. Every action carries its own proof of authority, checked in milliseconds before anything happens.
-
01
Send
The person, device or agent signs a Trust Packet for one specific action, with a key that never leaves the device.
-
02
Verify
The receiving service checks the signature against the signer's key in DNS, rejects replays and confirms the action is within scope.
-
03
Act
Only a verified action executes. Anything ambiguous is refused, and the outcome is kept as a tamper-evident certificate.
FOUR CRYPTOGRAPHIC PRIMITIVES, ONE AUTHORITY LAYER
Authority Anchors
Who holds the authority to act: a person, device or system with a domain-based key.
Trust Packets
Per-action proofs: signed, self-contained and non-replayable.
Authorization Certificates
Hash-chained records of multi-party sequences. Change one step and the chain breaks.
Authorization Ledgers
Append-only records each party keeps and can verify independently.
INDUSTRIES
Wherever an action needs authority
Payments, records, provisioning and agents all have the same gap. See what changes in each industry when the authorization layer exists.
Banking & Payments
Payee changes, transfers and card-not-present payments, each carrying proof it was authorized.
Learn more →ERP
Orders, refunds, supplier records and payouts that execute only with verifiable authority.
Learn more →Hospital & Healthcare
Record access, orders and claims, each tied to the clinician or patient who authorized it.
Learn more →Government
Benefits, filings and permits authorized by the person they belong to, before they are processed.
Learn more →University
Grades, aid disbursements and records, changed only with proof of who authorized them.
Learn more →Telco
Carrier actions bound to the subscriber's device, and carriers as verification operators.
Learn more →Device Makers
Keys in the Secure Enclave, so the device itself can authorize actions for its owner.
Learn more →AI & Cloud
Agents that act across domains, with each action carrying the authority delegated to it.
Learn more →INSIDE THE DEMO
Real apps, talking over HTTPS, trusting nothing but proof
UDA runs separate applications that call each other the way independent companies would. Every write that matters carries a Trust Packet, and every refusal shows you why. The recordings show it at work.
UDA ERP
A storefront, sales and procure-to-pay, where a supplier's bank change is held until it is verified.
UDA Banking
Pays suppliers for UDA clients, keeping a trust log of every packet it verified or refused.
UDA Hospital
Patient records and billing, the next app to gain signed actions.
GET STARTED
Sending is free. Verification is where value is exchanged.
Watch the recorded demos, or talk to the team about a live walkthrough, founding partner status and licensing.