PeerTalkID
PeerTalkID
Anonymous identity for the web

Passwordless, anonymous identity

No email. No password. No tracking. Twelve words give your users a permanent, anonymous identity that works on any device and every site that supports PeerTalkID.

No email or phone No IP address stored Free API & SDK
93%
Privacy score
0
Personal data stored
<10 min
Integration time
1 year
Session length
How it works

Twelve words. One click. A permanent identity.

Your secret never leaves the browser. The server only ever sees a public key and a signature.

1

A 12-word phrase

On first use, 12 BIP-39 words are generated locally in your browser. Write them down or download a backup card — they are your master key.

128 bits of entropy
Generated client-side
2

A key derived in your browser

The phrase is stretched with PBKDF2 (210,000 rounds) into an Ed25519 key pair. Only the public key is ever shared.

PBKDF2-SHA-256 → Ed25519
Server stores a hash of the public key
3

A signed challenge

To sign in, your browser signs a one-time challenge. The server checks the signature and issues short-lived tokens — no password involved.

Single-use challenges stop replay
1-hour access, 1-year rotating refresh

Automatic sign-in for a year

Same browser? One click and you're in. The session is encrypted in IndexedDB with a non-extractable AES-256 key; refresh tokens rotate silently.

Same words, every device

Enter your 12 words on any device or browser and you get the same identity — across every site that uses PeerTalkID.

Nothing useful to breach

The server keeps a SHA-256 hash of the public key — no IP, no email, no name. A database leak reveals nothing that identifies a person.

You stay in control

See your active sessions, sign out of every device at once and get notified about new logins.

Why PeerTalkID

Authentication shouldn't cost your users their privacy.

Traditional logins collect email addresses, IP logs and device data — all to answer one question: is this the same person as last time?

Traditional login

What is typically collected

  • Email address
  • IP address logs
  • Device fingerprint
  • Session metadata
  • Third-party SDK tracking
  • A password (hashed, but still a liability)
PeerTalkID

What we store

  • A SHA-256 hash of the public key — nothing else
  • No IP address, ever
  • No device data or metadata
  • No third-party SDKs
  • No password exists
  • Nothing personal to delete under GDPR
Privacy comparison

How PeerTalkID compares to the alternatives

Scored across seven criteria: data collection, IP logging, identity linkability, session encryption, third-party exposure, tracking and replay protection.

PeerTalkID Best
93%
Ed25519 signatures, AES-256-GCM session storage, no IP logs and a hashed public key. 128 bits of entropy.
WalletConnect
67%
Works for crypto users, but setup is complex, on-chain identity is exposed and RPC calls can be tracked.
Auth0 / Clerk
41%
Email required, IPs logged, devices fingerprinted and session metadata stored — compliant, but it collects a lot.
Sign in with Google
12%
Ties your real Google identity to every login and makes cross-site tracking possible.
FeaturePeerTalkIDAuth0 / ClerkGoogleWalletConnect
No email required
No IP address stored~
Unlinkable identity
Client-side AES-256 encryption~
One script tag integration~
Works without a backend~
No third-party tracking~
GDPR — nothing personal to delete~~
Free to integrateFree tier
Privacy score93%41%12%67%
Supported~PartlyNot supported
Live demo

Try it yourself

Click the button and create an identity in about 30 seconds. This is exactly what your users will see.

The demo uses the same embeddable button you can add to your own site.
For developers

One script tag. Any platform.

No API key and no registration. Drop in the button and your users can sign in immediately — verify tokens on your backend when you need to.

  • 1

    Load the script

    One <script> tag. Works with plain HTML, React, Vue, Next.js and more.

  • 2

    Add the button

    A single HTML element with light, dark and teal themes in three sizes.

  • 3

    Handle the callback

    Receive accountId and isPremium, then optionally verify the token server-side.

$npm install https://id.peertalk.chat/sdk/peertalkid-js-1.0.0.tgz
your-page.html
<!-- 1. Load PeerTalkID -->
<script src="https://id.peertalk.chat/peertalkid-button.js"></script>

<!-- 2. Add the button -->
<peertalkid-button
  theme="light"
  onlogin="onLogin"
></peertalkid-button>

<!-- 3. Handle login -->
<script>
function onLogin(session) {
  // accountId, isPremium, profile
  console.log('Welcome', session.accountId);

  // Optional: verify on your backend
  fetch('/login', {
    method: 'POST',
    body: JSON.stringify({ token: session.access_token })
  });
}
</script>

Browser client

Login, verify, refresh and logout in one small class.

import { PeerTalkID } from 'peertalkid-js'

Node.js server

Verify tokens server-side, with Express middleware included.

import { verifyToken } from 'peertalkid-js/server'

React

usePeerTalkID(), a provider and a ready-made button component.

import { usePeerTalkID } from 'peertalkid-js/react'
Licensing

Proprietary software, free to integrate.

PeerTalkID is proprietary software; all rights reserved. The privacy architecture — client-side key derivation, hashed public keys, no email or password — is documented in full on the developer portal.

Integrating PeerTalkID into your platform through the public API and SDK costs nothing. Redistributing or reselling the source code requires a written commercial license.

Read the license
  • API & SDK — free

    Use PeerTalkID login on any website or app at no cost.

  • Full documentation

    Endpoints, token format, security model and changelog on the developer portal.

  • Enterprise

    Premium features, dedicated integrations and SLAs on request.

  • Commercial license

    Source code licensing and white-label deployments — contact@peertalk.chat.

FAQ

Frequently asked questions

What happens if I lose my 12 words?
Your 12 words are the only way to access your identity on a new device. Nobody — including us — can recover them, because they never leave your browser. Write them down or download the backup card when you create your PeerTalkID. On a browser where you are already signed in, you stay signed in for up to a year.
Does PeerTalkID store my email or IP address?
No. There is no email field, no phone number and no password. The server stores a SHA-256 hash of your public key and short-lived session records; IP addresses are never stored.
What does a website receive when I sign in?
An anonymous accountId, whether the account has Premium, and signed tokens the site can verify with PeerTalkID. No name, avatar or personal data is shared.
Can I use the same identity on several devices and sites?
Yes. The same 12 words always derive the same key, so you get the same identity on every device and on every site that offers PeerTalkID login.
Do I need a backend to integrate it?
No. The button works on static sites. If you have a backend, send the access token to it and verify it with POST /api/verify or the peertalkid-js/server helper.
Is PeerTalkID open source?
No. PeerTalkID is proprietary software. The public API, SDK and button are free to use for integration, and the full security model is documented on the developer portal. Commercial source licenses are available on request.

Give your users a login that respects them.

One script tag. No personal data. Free to integrate.