Coming soon · omniauth.ai
OmniAUTH
Pair once.
Agents commerce forever.
Humans trust a merchant once. Agents subscribe, renew, and pay under your rules.
OmniAUTH binds who you’re allowed to deal with. OmniDROP seals the work. Circle settles the USDC.
A new paradigm for auth
Yesterday’s login was built for humans clicking “Approve.” Tomorrow’s buyers are agents — and they can’t pass SMS 2FA or fill checkout forms.
-
01
Human pairs the merchant
Key-bound Merchant Card. Fingerprint you can verify. Trust lands once.
-
02
You set the fence
Spend caps, allowlists, session limits — policy you write; agents obey.
-
03
Agents run the loop
Subscribe, renew, cancel, pay — AI-to-AI — unlocking sealed OmniDROP deliveries.
Product surface lands after XPRIZE submission. Domain secured. Story live.
Q-Day Readiness
Built for agents today.
Ready for quantum tomorrow.
Quantum computers will break today's public-key cryptography. When that day comes — Q-Day — every password vault, every stored credential, every long-lived secret becomes an open book. OmniAUTH's current signatures use Ed25519. That algorithm will need to be swapped. But the architecture? It was designed to survive exactly this moment.
Architecture beats algorithms
Traditional auth requires an architecture rewrite — new protocols, new credential flows, new trust models.
OmniAUTH swaps one cryptographic primitive (Ed25519 → ML-DSA). Same protocol. Same trust. Same agents.
Nothing to harvest
Password vaults are time bombs — "harvest now, decrypt later" attacks stockpile encrypted credentials for future quantum decryption.
Ephemeral proofs expire in seconds. There are no credential vaults to harvest. No long-lived secrets to decrypt. The attack surface doesn't exist.
Agent-native by design
Legacy 2FA — SMS codes, push notifications, TOTP — can't survive Q-Day because the human-in-the-loop assumption breaks for AI agents anyway.
Zero-password pairing was built for agents that can't type passwords or receive SMS. That same design needs zero changes for post-quantum.
Defense in depth
Single-layer crypto means one broken algorithm = total compromise.
Bilateral trust + CyberCop + ephemeral sessions mean even a compromised signature can't bypass spending fences, behavioral analysis, or mutual attestation.
The migration to post-quantum is a key swap, not a rewrite.
That's the difference architecture makes.