Docs / Overview

CogniKey Developer Documentation

CogniKey is the human authorization layer for the agentic era. Integrate the CogniKey REST API and Web SDK to add cryptographic proof of conscious human authorization to any action in your application.

Quick Start

The authorization flow has three steps: enroll a user once, challenge before each sensitive action, then verify the response to receive a signed attestation token.

POST /api/enroll

Creates a cryptographic commitment from the user's cognitive credential using scrypt KDF. No plaintext passphrase is ever stored or transmitted.

ParameterTypeDescription
user_idstringUnique identifier for the user
image_idstringIdentifier of the enrollment image
passphrasestring5–10 word description of the personal association (never stored)

POST /api/challenge

Issues a single-use 256-bit nonce with a 90-second TTL. The nonce must be passed to /api/verify. Expired or previously used nonces are rejected.

POST /api/verify

Validates the user's cognitive response against the stored commitment and returns an Ed25519-signed JWT attestation token valid for 5 minutes. Rate-limited to 5 failed attempts per 30-minute window.

GET /api/audit

Returns a tamper-evident chained audit log for a user. Each entry is SHA-256 chained to the previous, providing cryptographic proof of event ordering and integrity.

Web SDK

The CogniKey Web SDK provides React hooks and components for enrollment and verification flows. Compatible with React 18+ and React Native Web.

Security Model

CogniKey uses scrypt KDF (N=16384, r=8, p=4) for commitment derivation, Ed25519 for JWT signing, and crypto.timingSafeEqual for commitment comparison. No plaintext credential is ever stored, transmitted, or logged.

Changelog

v1.0 — Initial release. Enroll, challenge, verify, and audit endpoints. Ed25519 attestation tokens. Chained audit log.