NullLink is a zero-knowledge identity vault. Your credentials are encrypted in your browser — no server ever sees your data. Sign in once, use everywhere.
Three simple steps to own your digital identity — no accounts, no passwords shared with servers, no tracking.
Your NullLink ID is generated entirely in your browser using Ed25519 cryptography. Your private key is encrypted with a passphrase you choose — it never leaves your device unencrypted.
Add your name, email, phone, address, or any custom credential. Everything is encrypted client-side with XSalsa20-Poly1305 before being stored. The server only holds encrypted blobs it cannot read.
When a website needs to verify you, you sign a cryptographic challenge. When it needs your email or phone, you selectively share just that credential — sealed so only the recipient can read it.
Every design decision puts you in control of your data.
The server never sees your passphrase, private keys, or plaintext credentials. All encryption runs in your browser.
Use your NullLink ID across all compatible services — like "Login with Google" but you own the keys.
Choose exactly which credentials to share with each service. Your email for one, your phone for another.
Sign in with fingerprint or Face ID using the WebAuthn standard. No typing needed.
Every credential share is logged and encrypted. Only you can see what you shared, with whom, and when.
Log in via NL-ID, @alias, passkey, or QR code scan from your phone. Your vault, your way.
See how NullLink compares to conventional identity providers.
| Traditional Providers | NullLink | |
|---|---|---|
| Server sees your data | ✅ Yes — stored in plaintext | ❌ Never — zero-knowledge encryption |
| Provider can lock you out | ✅ Account can be suspended | ❌ You own your cryptographic keys |
| Tracks your activity | ✅ Login events, usage patterns | ❌ No tracking, no analytics |
| Choose what to share | ❌ Fixed scopes (email, profile) | ✅ Per-credential, per-field control |
| Cross-service identity | ✅ Same account across services | ✅ Same NL-ID everywhere |
| Works without app install | 🔶 Sometimes requires app | ✅ Browser-based, no install |
| Encrypted backup | ❌ Provider controls your data | ✅ Export encrypted backup anytime |
| Open cryptography | ❌ Proprietary systems | ✅ Ed25519 + XSalsa20-Poly1305 |
Log in if you already have a NullLink ID, or request an invitation to create one.
Log in with your NullLink ID to access your vault.
Enter an invitation code to create a new NullLink.
Choose a strong passphrase to encrypt your identity. This passphrase never leaves your browser.
Enter your NullLink ID (or @alias) and passphrase to unlock your vault.
Upload your encrypted backup file and enter the passphrase used when it was created.
Use this ID to log in anywhere that accepts NullLink.
Set up faster ways to log in — no need to type your full NL-ID.
Passkey (Biometric Login)
Add New Credential
Add an authenticator app for extra security.
Loading...
Every credential share is logged here. Only you can read these entries.
No sharing activity yet.
A desktop browser wants to log in with your NullLink ID.
Use fingerprint or Face ID — no typing needed
Or approve with alias + passphrase:
Enter your admin key to manage the Identity Vault.
Control whether new NL-IDs require an invitation code.
Create codes for new users to register their NL-ID.
Loading...
Loading...
Control which websites can use "Login with LinkID". Websites must be approved before they can make CORS requests.
Loading...
Loading...
Manually Add Origin
NullLink is progressively aligning with the Swiss Trust Infrastructure (swiyu) to participate in the Swiss e-ID ecosystem.
Discovery endpoints: /.well-known/did.json · /.well-known/nlid-configuration · /.well-known/openid-credential-issuer
Track progress on NullLink features and integrations.
Ed25519 signing, X25519 key exchange, XSalsa20-Poly1305 encryption, PBKDF2-SHA512 key derivation. All crypto client-side.
Biometric login, QR cross-device login, alias system. Multiple authentication methods.
User-controlled consent screen with per-credential selection. Only approved apps can request. Trust markers displayed.
NL-IDs published as W3C Decentralized Identifiers. Each user has a did:web document for interoperability.
Standardized credential schemas with URN identifiers, expiration dates, and version tracking.
Dynamic origin management with trust levels (Core / Verified / Unknown). Apps see verified badges.
Consent-based credential sharing for any website. Integration guide available.
Issue credentials in IETF SD-JWT VC format for per-field selective disclosure and cryptographic verifiability.
OpenID for Verifiable Presentations and Credential Issuance — standard protocols for swiyu interoperability.
Accept Swiss e-ID credentials via the swiyu Trust Infrastructure. Register as a verified issuer/verifier. Learn more.
Native app with hardware secure element binding, push-based login approvals, and offline vault access.
Everything you need to know about NullLink.
NullLink (NL-ID) is a zero-knowledge identity system. You create a cryptographic identity backed by Ed25519 keys. Your private key is encrypted with your passphrase in your browser — the server only stores an encrypted blob it cannot read.
Unlike traditional login providers, NullLink never sees your credentials. You control what to share, with whom, and when.
NLI-XXXXXXXXXXXX).Your identity cannot be recovered. The server never sees your passphrase — all decryption happens in your browser. This is the trade-off for true zero-knowledge security.
Recommendation: Save your passphrase in a password manager and export an encrypted backup file.
When a website or entity requests your credentials:
Yes. The server only stores encrypted blobs. Without your passphrase, the data is useless. All encryption uses industry-standard algorithms: Ed25519 for signing, X25519 for key exchange, XSalsa20-Poly1305 for encryption, and PBKDF2-SHA512 with 100,000 rounds for key derivation.
If you registered a passkey on the old domain ids.nulllink.ch, it won't work on nulllink.ch because WebAuthn passkeys are bound to the domain they were created on.
Solution: Log in with your NL-ID + passphrase on nulllink.ch, then register a new passkey. Your old passkey on the previous domain can be removed from your device settings.
Only encrypted identity blobs. We cannot read them.
Data is stored on servers in Europe under EU/GDPR data protection standards. Migration to Switzerland is planned.
You can export, delete, or lock your vault at any time. Since we can't read your data, there's nothing for us to misuse.
When you use your NL-ID to log in to a third-party application, that application is the data controller for any data you share with it. NullLink is not responsible for how third parties handle your data.
Privacy questions: privacy@onsteroids.ch
By using NullLink, you agree to:
NullLink is operated by Onsteroids GmbH, Switzerland.