Cybersecurity verification
Cybersecurity keys can be aimed at live or remote servers. Before that is allowed, you prove you control the domain those servers answer on.
Prerequisites
Cybersecurity also requires identity verification through Sumsub, so there is an accountable person behind the key. There is no separate age gate on this tier; age is gated by content, and only Roleplay serves adult content. See Age and identity.
Two methods, pick one
You prove control with either a DNS TXT record or a .merki challenge file served from the domain. Either one is sufficient. You do not need both.
- DNS TXT record. Publish a TXT record containing the challenge value at the domain.
.merkichallenge file. Serve a file at the well-known.merkipath on the domain, with the challenge value as its contents.
Challenge life
- A challenge is valid for at most 7 days.
- While a challenge is active, the Merki API re-checks it every 30 to 60 seconds.
- Renew the challenge before 7 days pass, or access is suspended and the key is revoked.
- Renew early: DNS propagation can take minutes to hours, so renew at day 6 at the latest. A challenge that lapses during propagation is treated as expired. There is no grace window after the 7 day maximum.
Domain rules
Two rules apply, and both surprise people:
- No wildcards. A domain pattern such as
*.example.comis not accepted. Name the exact hostname. - No subdomain propagation. Verifying a domain does not verify its subdomains. Verifying
example.comdoes not grantapi.example.comorstaging.example.com. Each hostname is verified on its own, with its own challenge.
Steps
- Choose a method: DNS TXT record, or
.merkifile. - Publish the challenge value for the exact hostname you want to use.
- Wait for the next check, within 30 to 60 seconds.
- On success, the hostname is verified and the Cybersecurity key can target it.
- Renew before the 7 day maximum (day 6 recommended). Repeat for every additional hostname.
If a check fails
A check fails when the TXT record is removed, the .merki file stops resolving, or the challenge passes its 7 day maximum. When that happens, access to the affected hostname is suspended and the key is revoked. See Revocation triggers.