freecoding.school100% FREE · NO SIGNUP
The Seven LayersISSUE #20 of 73

instance separation · auth without accounts

OMNIVSThe Silent Failure
OMNI saysInstance separation gives multi-domain auth without accounts — the instance’s existence is the auth.

§1c's auth model: because each instance is derived from a private seed, the very existence of a valid instance is the authentication — no username/password store. Different domains derive separate instances (BIP-32-style per-domain derivation), so a breach in one doesn't compromise another. Extra auth layers can sit on top, and device-as-auth is treated as a shortcut, not the foundation. metaSurf still gates each block.

Power-ups you unlock

The Silent Failure attacks — common mistakes

Boss battleExplain why per-domain instances limit breach blast-radius.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#b388ff;font-family:monospace;padding:20px"><pre>private seed → derive instance per domain
existence of a valid instance = auth (no account store)
domain A breach ≠ domain B (separate derivation)</pre></body></html>
▶ Open the interactive comic issue
‹ Genesis Loop · Public + Private SeedThe Fifteen Verbs · The Function Ontology ›