Live demo

Verify yourself.

Your screen emits a short sequence of coloured light. A real face returns it with depth, a corneal highlight and a pulse. A photograph, a replayed video and a generated face do not. Five seconds, and you'll see the assertion resolve exactly as an application would.

Your browser will ask for camera permission next. Frames are analysed and discarded. Nothing is written to disk, and no image is retained after the assertion is signed.

Coded illumination 0.00s
isHuman
isPresent
identityConfidence
deepfakeRisk
deviceTrust
sessionTrust
Illustration of the returned object. Press start for your own live result.
How the request arrives

A KeyDrop is one authorization, delivered once.

It lands by email carrying a single pending request. No app install, no enrolled device, no prior setup. Opening it on any browser with a standard camera starts the capture. It resolves the moment it is answered, and expires on its own if it is not.

No app install Any browser Standard camera Single use
Approved

The signed trust object returns to the relying party. The link is spent.

Declined

A receipt is sent, the link is revoked, and the account is left untouched.

Reported

The account locks for twenty-four hours and security is notified. Nothing was captured.

Expired

No action and no notice. The drop dies on its own.

What happens when you press start

Three steps, none of which send us your face.

01

You're handed off

A standard OAuth 2.0 authorization request moves you from the application to QueKey. The same flow you already use for Google or GitHub.

02

The screen interrogates

Seven illumination frames are emitted and read back. Photometric depth, corneal reflection, pulse and sensor forensics are computed from the response.

03

A trust object returns

The application receives an authorization code, exchanges it for a signed assertion, and reads six scores, never a photograph.

Recorded walkthrough

Watch it run end to end.

Imon Siddique, CTO, walks through a full passwordless authentication against a live application, presented at Atal Incubation Centre.

Before you press start

You are lending us a camera, not a face.

What is captured

Roughly five seconds of video at 720p, used to compute the liveness signals and a 512-dimensional embedding. The embedding is a set of numbers; a face cannot be reconstructed from it.

What is kept

For this demo, nothing. Frames are held in memory for the length of the capture and discarded once the assertion is signed or refused.

What the site receives

A signed token and six scores. The relying party, including this page, never sees an image, and never holds anything it could be breached for.