Domain-based keys establish who holds authority to act. Distributed via globally deployed DNS infrastructure and independently verifiable by any counterparty.
Make credential fraud structurally impossible
UniKey is the distributed authorization layer that verifies each action was authorized before it executes. Device-bound cryptographic proofs, validated in milliseconds through DNS.
Founding partners receive preferential commercial terms.
Per-action authorization proofs that are self-contained, cryptographically signed, non-replayable, and verified in milliseconds via DNS-based key lookup. Any ambiguity results in rejection.
Hash-chained records of complete multi-party transaction sequences. Each Trust Packet incorporates a cryptographic hash of all preceding packets. Modify any step and the entire chain breaks.
Process
Authorization proof in milliseconds
A simple route from setup to steady output.
Device signs the action
When a digital action is initiated, the originating device uses a private key stored in its Secure Enclave to sign a Trust Packet representing that specific action.
Verifier retrieves the public key via DNS
The corresponding public key is published in DNS records tied to the domain or device authority anchor, similar to DKIM. At least three independent DNS resolvers must return bitwise-identical key payloads per RFC-3001.
Trust Packet is validated
The verifier checks the signature in milliseconds. Trust Packets are non-replayable and unique to the specific action. Any ambiguity or failure results in rejection - the system fails closed.
Action executes with a permanent record
Authorization Certificates chain Trust Packets using cryptographic hashes, creating a tamper-evident sequence. Each party maintains an independent append-only ledger for permanent audit.
The toolkit
Four cryptographic primitives, one authorization layer
UniKey operates as Layer 2 between Identity (Layer 1) and Payment Execution (Layer 3), inserting cryptographic authorization proof into every digital action before it happens.
Authority Anchors
Domain-based keys establish who holds authority to act. Distributed via globally deployed DNS infrastructure and independently verifiable by any counterparty.
Trust Packets
Per-action authorization proofs that are self-contained, cryptographically signed, non-replayable, and verified in milliseconds via DNS-based key lookup. Any ambiguity results in rejection.
Authorization Certificates
Hash-chained records of complete multi-party transaction sequences. Each Trust Packet incorporates a cryptographic hash of all preceding packets. Modify any step and the entire chain breaks.
Authorization Ledgers
Distributed, append-only records that each party maintains independently. No reliance on central UniKey infrastructure or shared consensus. Permanent audit infrastructure by default.
Side by side
Not another identity or fraud detection tool
Plans
A protocol licensing model, parallel to Visa
Sending Trust Packets is free for all participants. Revenue is generated through verification fees, protocol licensing, and ledger services. Specific per-transaction fees and licensing costs are negotiated based on partner category and deployment scale.
Verification Fees
Micro-feesper Trust Packet verified
Metered infrastructure revenue that scales with billions of daily agent actions. No natural ceiling on volume.
- ✓ Sending Trust Packets is free for all participants
- ✓ Network operators earn per verification
- ✓ Scales with agentic commerce volume
Protocol Licensing
RoyaltiesARM-style open standard
Payment networks, telecoms, device manufacturers, and enterprise platforms license the protocol to operate verification endpoints.
- ✓ Open standard with licensed ecosystem
- ✓ Royalties by partner category
- ✓ Founding partners receive preferential terms
Ledger Services
Customdata intelligence products
Products derived from Authorization Ledgers including real-time fraud detection, compliance reporting, threat intelligence, and risk scoring.
- ✓ Real-time anomaly detection
- ✓ Automated audit trails for compliance
- ✓ Cross-network pattern analysis
- ✓ Authority chain risk models
Questions
Common questions
What is UniKey Protocol and what problem does it solve?+
UniKey Protocol is the distributed authorization layer for the internet, operated by Swoop In Technologies LLC. It solves a fundamental gap: the internet was built to move information but was never built to prove authority. Current systems verify WHO is acting, but UniKey verifies that the SPECIFIC ACTION was authorized before it executes. This matters because stolen credentials can pass identity checks, enabling over 80% of all data breaches and contributing to $442B in global fraud losses in 2025. UniKey operates as Layer 2 between Identity (Layer 1) and Payment Execution (Layer 3).
How does UniKey Protocol technically work?+
UniKey operates through four cryptographic primitives. Authority Anchors establish who holds authority via domain-based keys distributed through DNS. Trust Packets are per-action authorization proofs that are self-contained, cryptographically signed, non-replayable, and verified in milliseconds via DNS lookup. Authorization Certificates chain Trust Packets using cryptographic hashes, creating tamper-evident records where modifying any step breaks the entire chain. Authorization Ledgers are distributed, append-only records that each party maintains independently without relying on central infrastructure.
How is UniKey different from existing identity and fraud prevention systems?+
UniKey is not a competitor to identity systems, fraud detection platforms, or settlement networks. It operates at a layer they do not address. Identity systems like SSO, MFA, or biometrics verify who is acting. Fraud detection systems analyze patterns after or during a transaction. UniKey verifies that the specific action itself was authorized before execution. The core distinction is that UniKey does not detect fraud. It makes scalable credential-based fraud structurally impossible, because every action requires a Trust Packet signed by a key that never leaves the device.
What is the security foundation?+
UniKey inherits its security model from DKIM signing and DNS-distributed public keys, the same primitives securing legitimate email at internet scale. Keys are stored in device Secure Enclaves with explicit validity periods of 90 days maximum for high-assurance deployments and no-gap rotation. DNS validation requires at least three independent DNS resolvers returning bitwise-identical key payloads per RFC-3001, ensuring the system fails closed on any ambiguity. Six published RFC-style specifications govern the protocol, all publicly available on GitHub.
What validation and review has UniKey received?+
UniKey has 100+ patents granted and pending across multiple jurisdictions. A NIST NCCoE submission is in progress as a recommended solution for the AI Agent Identity and Authorization framework. An independent threat-model review has been completed by Black Duck Software. Six RFC-style specifications (RFC-1000, RFC-2001, RFC-3001, RFC-1300, RFC-5003, RFC-1200) are published and publicly available on GitHub.
Move forward
Make fraud structurally impossible
Book a call to explore how UniKey Protocol fits your authorization infrastructure. Founding partners receive preferential commercial terms.
Book a call→