Trust model
Authority that stays with the human—and the bank.
How Keyra separates authentication from authorization, binds transactions, and keeps recovery from becoming a soft backdoor.
Authentication vs authorization
Authentication is not the end state.
- Who are you?
- Can we trust the credential?
- Did you authorize this exact action?
Banks do not only need confidence about who entered a session. They need evidence of who authorized the consequential financial instruction.
Deterministic evidence
From session logs to instruction-bound proof.
Stop asking “Did something happen?” Start asking “What credential approved what instruction?”
Traditional
Login log
- Session opened
- MFA passed
- Channel authenticated
No record of the specific instruction that was approved.
Keyra
Transaction-bound authorization record
- Customer reference
- CUST-4417-2098
- Credential reference
- CRED-8F21-A004
- Action
- OUTBOUND_WIRE
- Amount
- 250,000.00 USD
- Destination
- XYZ CORPORATION
- Timestamp
- 2026-08-29T14:02:11Z
- Challenge
- NONCE-7C4E…
- Signature verification
- VALID
- Credential status
- ACTIVE AT TIME OF USE
- Policy applied
- WIRE > 100K — HUMAN AUTHORITY
- Decision
- APPROVED
- Audit reference
- AUD-2026-0829-118
Verifiable after the event.
Cryptographic evidence does not independently establish subjective intent or resolve every legal dispute.
Threat model
A credible security proposition states its limits.
Hardware credential
Strongly addressed by hardware credential
- Credential phishing
- OTP interception
- SIM swap
- Certain credential replay
- Verifier credential theft
Transaction binding
Improved through transaction binding
- In-session transaction manipulation
- Beneficiary manipulation
- Instruction alteration
Limits
Not solved by hardware alone
- Authorized push-payment scams
- Social engineering with knowing approval
- Physical coercion
- Insider collusion
Complementary credentials
This complements passkeys. It does not compete with them.
Passkey
Everyday login- Phishing-resistant
- Platform/device recovery
- Excellent everyday login experience
Keyra trust card
High-consequence authority- Hardware credential
- Bound to physical card
- Bank-issued
- Can support transaction-bound authorization
- Off-device physical credential
Use passkeys for everyday login. Reserve hardware authority for events where consequence or evidence requirements justify it.
Selective disclosure
Answer the question. Disclose nothing else.
Service asks
“Is this person over 18?”
Conventional
Upload full identity document
Keyra credential model
Signed assertion that condition is satisfied — no unnecessary DOB exposure.
- Minimum necessary disclosure
- Customer consent
- Purpose limitation
- Cryptographic verification
- Auditability
Recovery
Recovery is where trust chains break.
Card temporarily mislaid
Pause credential.
Card lost or stolen
Revoke credential with card.
Replacement issued
New card. New key pair. Nothing copied from old key.
Recovery without card
Bank re-verifies customer using bank-controlled recovery process.
The effective assurance level is set by the weakest recovery path.
