Testnetv1.3.0
Checking…PQ…
Galaxia

Galaxia ID

Testnet SSO for the Galaxia ecosystem

Chart the Unknown Possibilities of Existence.

TestnetHybrid HMAC + ML-DSA-65Wallet bind requiredNot quantum-proof · Mobile PQ SIMULATED

Enterprise SSO (wallet signature required)

Challenge-bound hybrid credentials (HMAC + live ML-DSA-65 server signing — not quantum-proof). One-time gid_code handoff — tokens never in the URL. Wallet binding (classical EIP-191) is enforced on this server; sign-in cannot complete without a wallet signature. Confirming server policy…

Testnet · Hybrid PQ-capable (not quantum-proof) · No mainnet claims · SOC 2 / GDPR certification require external audits · Mobile PQ is SIMULATED

Galaxia ID Maturity

Honest capability map for investor and technical due diligence. No mainnet claims.

Challenge-bound hybrid SSO

Implemented

HMAC + live ML-DSA-65 (@noble/post-quantum). Unbound DID minting disabled. Hybrid — not quantum-proof.

One-time handoff codes

Implemented

gid_code exchange — access/refresh tokens never placed in redirect URLs; validate prefers handoff-only.

Fail-closed PQ health

Implemented

ML-KEM / ML-DSA / SLH-DSA live self-tests (cached ~60s on health); 503 unless all pass.

Redis session storage

Implemented

Upstash Redis for handoff/revoke/audit when UPSTASH_* set; memory fallback with health warning.

Wallet-bound issuance

Implemented

EIP-191 bind required by default in production (GALAXIA_ID_REQUIRE_WALLET_BIND). Demo unbound only with explicit allow.

Mobile NIST PQ

Planned

Permanently marked SIMULATED on React Native — do not claim real PQ or quantum-proof.