Assure

Email Verification Protocol demo

WICG Email Verification Protocol — origin-trial prototype

Email verification, end to end in the browser

Assure is a working prototype of the Email Verification Protocol, built for the teams specifying and launching it. It covers both halves of the protocol: a relying-party verifier that captures and validates Email Verification Tokens through a 9-step server-side pipeline, and a live spec-shaped issuer with DNS delegation, a published JWKS, and an issuance endpoint — plus EVP-based sign-in, account creation, and deployment diagnostics.

What's implemented

Assure exercises both halves of the protocol — the relying-party (verifier) side and a working issuer — plus the operational tooling needed to debug a real origin-trial deployment.

Guided verifier walkthrough

A 5-step flow: environment check, token capture (autofill hidden field plus the emailverified event), a 9-step server-side verification report, and a final policy decision. Runs in three modes — live EVP on the registered origin, simulated credentials everywhere else, and a labeled unavailable path with a prerequisites checklist.

Run the walkthrough

Live demo issuer

A spec-shaped issuer running on verify.assure.chat: /.well-known/web-identity, an issuance endpoint, a published jwks.json, DNS delegation via the _email-verification.assure.chat TXT record, and an issuer health endpoint.

Open the Issuer Console

Server-side validation pipeline

Nine verification steps server-side: SD-JWT and key-binding JWT signature checks tolerant of multi-key JWKS documents, issuer discovery over DNS-over-HTTPS, and nonce and origin binding on every credential.

EVP login & account creation

Passwordless sign-in backed by Lovable Cloud: every verified sign-in creates or reuses a real user account in the auth database, registered @assure.chat issuer accounts, and verified-email-only identity (the protocol deliberately provides no name or phone number).

Try EVP sign-in

Diagnostics & telemetry

Environment detection (Chromium vs. iOS WebKit, HTTPS, registered origin, origin-trial token presence), issuer readiness checks (DNS delegation, metadata reachability, sign-in state), and per-attempt token-delivery telemetry.