Offline authenticity. Online policies.RRID — tokens with one-click verification.
Ed25519 signatures, contextual policies and privacy-first telemetry. For CTOs, integrators and brands that need verifiable authenticity offline and at the edge.
- Step 1. Token issuance
Issuer generates RRID: payload + policy + Ed25519 signature. Output as QR / NFC / PDF.
- Step 2. Offline verification
Mobile app or device verifies the signature offline without touching the network.
- Step 3. Online policies
Optional check for limits and bindings. Edge + CDN caching with 99.9% SLA.
- Step 4. Telemetry
Aggregate events without PII. Export-ready for SIEM/BI via events/metrics formats.
RRID product stack
Compact tokens, offline verification and enterprise-ready policies. An engineering stack without magic.
Ed25519 offline
Signature verified locally in milliseconds. Zero-trust without touching the network.
Policies & attestation
Limits, geo/time windows, grace periods. Online layer over HTTP/gRPC, edge or on-prem.
SDK & format
Open RRID format, REST API, iOS SDK, ready-made samples for Swift/Kotlin/TypeScript.
Privacy by default
Anonymisable telemetry. Disable entirely or deploy inside your own perimeter.
Download the architecture whitepaper and see how the RRID modules fit together.
Control you can explain
Define policies through UI or IaC. Apply contextual restrictions while grace periods are surfaced directly in the client.
Limits & grace
TTL, counters, usage windows and progressive grace periods.
Bindings
Bind to device, user, GeoIP or service area.
Edge / on-prem
Cloudflare Workers, AWS Lambda@Edge or fully on-prem Kubernetes.
DevX
CLI, Postman collection, Terraform module for policy rollout.
Anonymous analytics
RRID collects just the minimum events: verification fact, issuer, key id and status. No PII stored. Telemetry is available via Plausible, BigQuery or S3.
- Offline/online verification reports
- SIEM export (Splunk, ELK, Sentry)
- JSON Lines data model
Choose your rollout lane
Flexible delivery models: managed cloud, air-gapped on-prem or hybrid for sensitive validations.
Cloud
- Global CDN
- 99.9% SLA
- Reports & alerts
On-prem
- Air-gapped mode
- K8s/VM scripts
- Per issuer licensing
Hybrid
- Public verifier
- Private policies
- VPN / mTLS
Integrate without the pain
SDKs, APIs and production-ready examples. Includes Postman collection, Terraform, Helm chart and sample tokens.
Stable schemas with curl and gql examples.
Swift Package, offline verification, sample app.
Kotlin multiplatform with Jetpack Compose UI.
React hooks, WebCrypto, WebAuthn bridge.
rrid-cli for issuing and verifying tokens.
HubSpot, Pipedrive, Zapier or SMTP.
Where RRID already works
From manufacturers to SaaS — RRID helps eliminate fakes, control access and accelerate pilots.
RRID on packaging, in-store offline checks, edge revocation and Grafana monitoring.
API product with limit policies, device binding and web verification for clients.
Grace periods, cached policies, offline operations up to 48h, anonymous telemetry.
What teams say
CISO, engineering and operations leaders already running RRID in production.
RRID helped us digitise dealer audits. The pilot took three weeks and we simply scaled the scenario afterwards.
We replaced the zoo of API keys with RRID tokens for partners. Now we have a verifiable view of limits and SLAs in real time.
Offline availability is critical for us. RRID guarantees couriers operate within policy even with no connectivity.
See how RRID fits your stack
Request a pilot — we will send scenarios, SDKs and a security checklist. We respond within one business day.
Frequently asked questions
How does offline verification work without network?
Ed25519 signatures are verified locally; no network access for libraries is required. Policies sync later or are enforced at the edge.
How do you rotate keys?
We support multiple active keys, grace periods, automatic JWK publication and fast revocation.
Do you support token revocation / CRL?
Yes: short TTL plus online revocation by RRID or batch. Distributed through CDN and webhooks.
What about SLA and on-prem?
Managed edge comes with 99.9% SLA. On-prem ships with Ansible/K8s automation and certification support.
How is pricing structured?
Tiers based on issuance and verifications. Pilots are free, enterprise is custom.
What about privacy?
Telemetry is pseudonymised with no PII. You can self-host and keep the data locally.