Ydenticator logo

Proprietary 2FA — only you know who you are

Ydenticator is a next-generation two-factor authenticator that binds every code to three factors: something you know (a private 30-question profile), something you are (your device biometrics), and something you own (the device itself). A stolen phone, a leaked seed, or a compromised inbox is never enough to sign in as you.

Adaptive challenge

A 30-question profile becomes the private key behind every code. Each request asks a different question, verified server-side, with lockout after repeated mismatches.

Hardware-backed

Your profile is encrypted with AES-GCM-256 using a non-extractable key derived via WebAuthn PRF — anchored in Face ID, Touch ID, or Windows Hello. The key never leaves the hardware.

TOTP multidevice

Register any RFC 6238 provider by scanning its QR code, with replay protection and audit logging. Enroll a second device with a signed one-time link — no cloud sync of seeds, ever.

Zero-knowledge recovery

Opt in to 10 single-use recovery codes, each independently wrapping your profile with PBKDF2 + AES-GCM. Export as a password-protected PDF. Rate-limited to 10 attempts per 15 minutes to defeat brute force.

Installable private PWA

Install Ydenticator to your home screen on iOS, Android, or desktop. GDPR-compliant, TLS 1.3 with post-quantum key exchange end-to-end, and no third-party trackers.

How Ydenticator works

  1. Create your key by answering 30 yes/no questions. Your profile is scored across Explorer, Thinker, and Performer categories and encrypted on this device with a hardware-bound key.
  2. Add service providers by scanning their 2FA QR codes. Standard-TOTP URIs are auto-detected so codes are accepted by GitHub, Infomaniak, Discord, and every RFC 6238 service.
  3. When a code is needed, Ydenticator asks one random question from your profile, verifies the answer server-side, releases the code once, and signs you out immediately.
  4. Lose a device? Restore your profile on a new one with a recovery code — each code burns on use, so no code is ever valid twice.