How are devices trusted, and what happens on revocation?

Created by Fu Yi, Modified on Tue, 28 Jul at 4:18 PM by Fu Yi

At enrollment, each phone generates a key inside its secure hardware; the server keeps only the public half. Every request from the phone is signed — method, path, body hash, timestamp — and no signature is accepted twice. Revoking a device is one action with immediate effect: its keys and refresh-token families are severed, and the user re-establishes access by presenting their face on a new device.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons

Feedback sent

We appreciate your effort and will try to fix the article