HYBRID DEVNET · PUBLIC EVIDENCE LIVEVerifiable infrastructure for value, markets, identity, and operational dataInspect the network
Getting started

What is Hybrid-ID, and what does signing in let me do?

4 min read

Hybrid-ID is the identity experience built on Hybrid-Chain's identity infrastructure. It lets an established Hybrid account sign in to participating applications, beginning with Hybrid-Chain. Each application still decides which workspace, information, and operations that person may access. Signing in does not automatically share private business context, authorize an agent, or permit a payment.

A returning identity, an application's own workspace

A participating application can recognize a person returning through Hybrid-ID and restore the workspace or preferences it already maintains for that person. That is useful continuity, but it is not a shared database of everything the person has done elsewhere. Each application keeps its own session and application data. It must check current organization membership and resource permissions before showing protected information. Recognizing an account is the starting point for those decisions, not a replacement for them.

What an application integrates today

The registered web-application flow uses OpenID Connect Authorization Code with PKCE S256. The application sends the person to Hybrid-ID, validates the resulting identity response, and establishes its own session. Independent applications should not collect the person's Hybrid password. The canonical provider is auth.hybrid-id.com; its public discovery document supplies the protocol metadata. The developer guide explains operator registration, exact HTTPS callback URLs, and approved scopes. Applications recognize accounts using the validated issuer and subject, rather than assuming an email address is a universal identifier across services. Pairwise subjects give unrelated application sectors different identifiers.

Verification is an additional decision

Some workflows need a verified attribute or credential before enabling a feature. Others need only ordinary account authentication. The receiving service defines that requirement and evaluates the issuer, scope, status, and meaning of the credential it accepts. Supported privacy proofs can help limit disclosure for a particular check, but planned proof contracts should not be described as callable features. A technically valid credential does not establish every claim about its holder, and a successful sign-in does not automatically satisfy a service's verification policy.

Agents need their own permitted role

Hybrid-ID's direction includes a coherent identity experience for people, organizations, and the agents they authorize. That unified agent access remains in development. Current integrations use confirmed workload bindings, reviewed-context access, and policy services for their distinct purposes. For example, a purchasing assistant could read a collection approved for its workload and prepare a proposal. The application must separately establish that authority; it cannot derive it simply from the buyer's successful sign-in. Reading context does not grant access to every private source document or permission to spend.

A practical way to evaluate the connection

Choose a participating application and a narrowly defined business task. Confirm the application registration and account-access route, then check that a returning person reaches only the workspace they are entitled to use. Test the application's behavior when membership or a required product permission is absent. If an agent is involved, identify its actual workload authority and the context it may receive. Retain enough non-sensitive evidence to explain which identity, permission, and operation were checked. The benefit is a familiar route into connected work, with each service retaining clear responsibility for what it allows.

Conditions & limitations

OpenID Connect sign-in is available for registered applications. New accounts remain invitation-only, self-service client registration is unavailable, and unified agent access is still in development. Optional credentials and proof operations retain their own permissions and availability.

What to do next

Start with the Hybrid-ID integration guide for your application, then identify the separate product permissions your intended workflow needs. Confirm application registration and account access before planning an evaluation.