background gif
The post-credential era starts here

Kill the key. Long live the proof.

Passwords, tokens, and certificates keep working until someone rotates or revokes them - including an attacker who already has a copy. ENI6MA replaces that lasting authority with one-shot proofs: each approval authorizes one action once, across apps, agents, and paper. Captured proofs do not replay; authority ends with the request. Deploy as Public, Cloud, or Sovereign stacks under the reference architecture and model-scoped claims.

One-shot proofs across digital systems and paper. Authority expires with the request - under the reference architecture and claim model.

Stored secret vs one-shot proof

Read left-to-right: the stored-secret column shows ambient credentials that keep working after copy; the one-shot column shows a request-bound envelope that burns after accept. Takeaway: stolen possession is not lasting authority when the proof dies with the moment.

Applied Scenarios

Browse all scenarios
Microsoft logo
JPMorgan Chase logo
Walmart logo
Exxon Mobil logo
Boeing logo
Pfizer logo
Amazon logo
Procter & Gamble logo
Goldman Sachs logo
Tesla logo

Illustrative scenarios. The organizations named and the logos shown are publicly documented reference organizations, not ENI6MA customers. No commercial relationship, deployment, or endorsement is claimed or implied.

ENI6MA replaces reusable credentials with one-shot, request-bound proofs. Authority expires with the request under the reference architecture (claim: authority-expires-per-request).

Enterprise installs it. People feel it.

Fewer support fires. Fewer lasting break-ins.

Companies install it to save time and money. People get safer logins where they already are.

What you stop relying on - and what you keep

Retire the reusable-credential breach surface. Keep the IdP, mTLS, and application systems you already run; Gate layers one-shot request authority on top.

Eliminate

  • Reusable passwords as lasting authority
  • Standing API keys and bearer tokens
  • OTP MFA as lasting authorization factor
  • Biometric templates as lasting secrets

Deny (scoped)

  • Replay (claim: replay-impossible)
  • Phishing-for-capability (claim: immune-phishing)
  • Vault-breach-as-takeover (claim: immune-vault-breach)
  • Keylogging of a reusable secret (claim: immune-keylogging)
  • Learning the secret from the public channel under the named model

Works across

  • AI agents and MCP tool calls
  • APIs and workloads behind Gate
  • Mobile and desktop web
  • Air-gapped Foundry and Control deployments
  • Physical Paper Identity Proof sheets

Ambient credentials are the breach

Every API key, bearer token, and service certificate in your estate works from anywhere until you notice it is gone. ENI6MA closes that open: a stolen key is not lasting capability, and revocation is one registry state change under the reference architecture - the verifier observes allow or deny for that request alone.

Ambient credentials invite breach

Ambient API keys, bearer tokens, and certificates as stealable tokens leading to breach

Possession is not authority

Token-copy chain showing possession mistaken for authority at agent scale

Capture is not knowledge

Follow the observer path: a full transcript fills the notebook while the vault for the secret stays closed. Surface bits are recordable; effective mutual information with the secret stays empty under the model. Takeaway: capture of the channel is not knowledge of the secret.

Every API key, bearer token, and service certificate is a secret that works from anywhere until you notice it is gone.Ambient credentials authorize by possession alone; ENI6MA replaces that model with one-shot, request-bound proofs.

Theft expires with the request

An API key, bearer token, or service certificate works from any path that can present it. ENI6MA binds authority to one request so a captured secret cannot authorize a second call under the reference architecture.

Revoke once in the registry

Ambient revocation is a fleet rotation campaign. With circuit handles in Control, deactivation is one registry state change every consulting Gate observes on the next proof.

Each agent tool call is one-shot

MCP tools and autonomous agents mint long-lived secrets faster than humans. Per-call envelopes wrap each tool invocation so Gate/policy authorizes world-changing side effects once - not lasting request authority under the reference architecture.

Product capabilities

Cloud. Agent. Human.

One family of one-shot proofs: stolen secrets stop granting lasting capability, agents authorize each tool call once, and people prove without a reusable password or biometric template as lasting authority.

One proof family

Three surfaces (cloud, agent, and human) share one envelope primitive rather than three incompatible credential schemes. Read the shared core first, then the surface-specific ceremony wrappers. Takeaway: Channel Zero is one proof job expressed across form factors.

Status quo vs ENI6MA outcomes

What lasting credentials force you to accept versus what one-shot authority changes: captured secrets stop granting lasting power, replay fails under the reference architecture, and revocation is one registry change. Each absolute cites its claim ID.

One-shot vs reusable credentials

Compare the reusable-credential lifetime on the left with the per-request one-shot proof on the right. Reuse invites steal-and-replay; one-shot authority dies after burn. Takeaway: the same word “proof” can mean lasting possession or momentary ceremony work.

Status quo
ENI6MA
Secrets, tokens, and vaults grant lasting power

No lasting power from a captured secret

Authority expires at the end of each request.The envelope binds method, endpoint_id, request hash, policy hash, tau, and nonce (one message, one use).Holds under the reference architecture

Replay is a hygiene problem

Replay fails under the reference architecture

Replay is impossible by design.The nonce is burned before validation in a durable ledger; it is spent even when validation later fails.Holds under the reference architecture

Phishing harvests a lasting credential

No reusable credential to harvest for lasting capability

Immune to phishing.No reusable credential exists to harvest; endpoint_id binding means a relayed proof fails on any other route.Holds under the reference architecture

Vault dump equals takeover

Identity is not a vault of reusable secrets

Immune to credential-vault breach.No vault of reusable secrets exists; identity is compiled into the circuit binary, not stored as a transferable credential.Holds under the reference architecture

Revocation is a fleet-wide rotation

One registry state change deactivates the handle

Revocation is one state change.Deactivating a circuit handle in the registry revokes the identity; there is no rotation campaign across every workload.Holds under the reference architecture

Agent and MCP ambient keys authorize tool side effects

Per-call authorization for tool side effects

Authority expires at the end of each request.The envelope binds method, endpoint_id, request hash, policy hash, tau, and nonce (one message, one use).Holds under the reference architecture

No paper or offline identity path

Paper Identity Proof without biometric templates as lasting authority

Air-gapped minting is rare

Foundry sovereign and air-gap capable minting for estates that cannot leave the network

Full mechanism detail on Security architecture. Guarantees assume the reference architecture. Compare security systems in depth on the Math comparison matrix.

Applied scenarios

Illustrative architectures against publicly documented reference organizations - role-based access, financial API binding, regulated workload control - not customer engagements or endorsements.

Browse all scenarios

Scenario reference architecture

Generic applied-scenario reference architecture template

Illustrative scenarios. The organizations named and the logos shown are publicly documented reference organizations, not ENI6MA customers. No commercial relationship, deployment, or endorsement is claimed or implied.

Live capture

Security guided tour

Twenty-nine screens from a live DEMO-HACK red-team run, burn-before-validate, envelope binding, and every reject stage, with hotspot callouts and payload excerpts.

Security guided tour

Guided tour stack: health, allow, attacks, mint

How a Gate decides

Eight fixed checks run before application logic: bind the request, spend the nonce, then allow or deny. A second submission of the same envelope fails under the reference architecture (claims: burn-before-validate, replay-impossible).

  1. Recompute the request hash

    The gate hashes the body it actually received and compares it to the envelope.

    Rejects: A body that was altered after the proof was made.

  2. Check endpoint and policy

    The envelope names the endpoint and the policy it was made for; both must match this route.

    Rejects: A valid proof relayed to a different endpoint.

  3. Confirm the circuit is active

    The handle is resolved against the registry and must be active. Deactivating a handle is how revocation happens.

    Rejects: A proof from a revoked identity.

  4. Check freshness

    The envelope timestamp must fall inside the freshness window configured for the route.

    Rejects: A captured envelope replayed after the window closed.

  5. Burn the nonce

    The nonce is spent here, before the proof is validated. Every submission spends it, including one that is about to fail validation.

    Rejects: Any second use of the same envelope. This is where replay dies.

  6. Validate the proof

    Only now is the proof itself checked, against the local binary or the registry. Both modes are equivalent at the envelope layer.

    Rejects: A forged or malformed proof.

  7. Apply application policy

    Ordinary authorization runs in the post-proof zone: arguments, limits, and business rules.

    Rejects: A well-proved request asking for something it is not allowed to ask for.

  8. Serve the request

    The application does its work, and the response is bound back to the request that earned it.

How a Gate decides

Read the pipeline left-to-right: each Gate stage checks binding, freshness, and burn order before allow. Gold highlights burn-before-validate so replay dies at the ledger, not after crypto. Takeaway: enforcement order is part of the security claim, not a UX detail.

Replay dies at the ledger

Duplicate ceremony rejected at ledger via burn-before-validate

Burn-before-validate is the structural reason a second submission of the same envelope always fails.ShippingGate stage 5 spends the nonce in the durable ledger before stage 6 validates the proof.Holds under the reference architecture

Replay is impossible by design.ShippingThe nonce is burned before validation in a durable ledger; it is spent even when validation later fails.Holds under the reference architecture

The verifier observes allow or deny for that request alone - not a reusable authorizer. Formal model and axioms live on Technology · Axioms.

Mint. Revoke. Enforce. Prove.

Foundry mints identity. Control revokes with one registry state change. Gate enforces one-shot authority on the request path. Verify proves the reject stages before production traffic does.

Four authorization planes

Read top-to-bottom through Foundry (mint twins), Control (registry and ledger), Gate (request boundary), and Verify (adversary harness). Each band is a different ops job that ships the same proof family. Takeaway: the product stack separates integrity tooling from the empty-channel authorization thesis.

Full catalog and form factors on Products.

Technology · Math

The formal case, when you need it

Public transcripts can be recorded without teaching the secret under the named model. Open Math for axioms, bounds, and claim scope - this page stays on buyer outcomes.

When you need the formal case: under the named model, recording the public channel need not teach the secret. Download New Dimensions or open Math for axioms, bounds, and claim scope.

Download New Dimensions · Math hub · Read the Math

Two kinds of security

Two columns contrast a computational hardness assumption with empty-channel authorization. Takeaway: not every security claim is the same kind of guarantee.

This plate contrasts a computational public artifact whose inverse exists but is hard with a zero-information channel whose public scaffold displays every path while the private selector remains outside the observable boundary.

Read left-to-right: computational hardness assumptions bound the adversary; the zero-information panel relocates confidence to transcript emptiness. Takeaway: long-horizon security moves from recoverable-archive cost to the information content of the channel.

Technology · Fundamentals

Prove once without teaching the channel

Capture is not knowledge under the named model. Fundamentals walks the empty effective channel into Rosario, Overview, and the published corpus.

Prove knowledge once without teaching the channel what you know. Overview, Channel Zero, Rosario, and Papers collect the pedagogy and published corpus.

Fundamentals path · channel reveals nothing

A fundamentals path plate: when the channel reveals nothing, capture is not knowledge. Takeaway: Channel Zero sits beside familiar crypto primitives with a different job.

Protect a high-risk route

Start with Gate on one high-risk route and observe allow or deny - including replay fail. Or request a Foundry evaluation for licensed cohort manufacturing and Control under Public, Cloud, or Sovereign packages.

Protect an endpoint

Minimal wrap-this-route diagram for protecting an endpoint

Need executive delivery alongside the product? Fractional CAISO lives under Services. Services

Put Gate on one high-risk route and observe allow or deny - including replay fail - or talk to us about Foundry and Control under Public, Cloud, or Sovereign packages.