English · Français
A compact page for evaluators. Source, docs, and local setup live in the public MIT repository: github.com/mgagp/ezkey. See also Source code & evaluation.
Ezkey is backend-first cryptographic MFA: your integration backend and the mobile app participate in an explicit chain of enrollment and authentication. The browser is not the center of the ceremony.
The project aims to be materially stronger than passwords and classic TOTP-style flows for some self-hosted, backend-oriented contexts. It is not a WebAuthn / FIDO2 implementation and does not claim formal equivalence to those ecosystems. Ezkey is alpha — not production-ready and not Duo / Okta / Keycloak parity.
Security posture reflects deliberate, opinionated trade-offs. For the maintainer’s framing of limits and ambition, see Why Ezkey exists.
License: MIT. The main repository is public on GitHub: https://github.com/mgagp/ezkey. There are still no published release packages. Progress notes remain on Monthly digests.
Use security@ezkey.org. Do not use public GitHub issues for suspected vulnerabilities. The published policy is SECURITY.md in the repository.
Prefer the in-repo docs; use this site for high-level evaluation material:
docs/, clean-start)