Proof, not promises.
The same wire format the chain itself verifies, canonical challenge, keccak digest, recovered signer. Try the live cryptographic loop below; the OIDC bridge (services/siwg-bridge) wraps it so any website can add the button like any other login provider.
Sign in with Genesis
No email. No password. No account database. You prove ownership of a chain key by signing a challenge, the site recovers the signer from the signature and never learns anything more.
No account yet? Create one first, the account IS the key pair, generated and sealed in your browser, with your Genesis Name, identity bond, and legacy vault set up alongside it.
With the Genesis wallet extension installed, it signs this challenge and the key never leaves it. Without it, demo mode: a throwaway key is generated in your browser and discarded on sign-out. Challenge origin: genesisprotocol.io.
challenge = {"version":1,"origin":…,"purpose":"login","nonce":…}
digest = keccak256(canonical JSON) · sig = 65-byte r‖s‖v
address = bech32(keccak(recovered_pub)[12:]), claimed address is never trusted
No accounts, anywhere
There is no account database to breach. Identity is a chain key; the site verifies a signature and stores nothing but your public address.
Reputation travels with you
Your Genesis Score, verified-human status, and name (xlawless.gen) can be presented at login, selectively, per site, with consent.
Prove predicates, not identities
Verifiable credentials let you prove '18+' or 'GS ≥ 700' without revealing your name, address, or birthdate. Google login cannot do this.
Agents log in on your terms
Delegate scoped, revocable, spend-capped sessions to your AI agents, with the chain-level kill switch already built into x/agent.