HashBack
PulseGate's liveness check found it on 7 Oct 2026; it is registered on GitHub and has been in the index since 7 Oct 2026. How this is checked
HashBack is an open-source authentication mechanism for server-to-server HTTPS communication. It uses existing TLS identities and a two-request challenge flow so services can verify one another without retaining long-lived secrets.
Inferred · not functionally tested
Overview
5 featuresPurpose: Authenticating internet-facing services without storing passwords, API tokens, or private keys.
Inferred · not functionally tested
Audience: backend developers and platform engineers
Inferred · not functionally tested
Functions: Unknown
Interfaces: API: indicated (inferred, not tested) · MCP: unknown · CLI: unknown · Self-hosting: indicated (inferred, not tested)
Recorded constraints: pricing: open_source · license: MIT · platforms: WEB · deployment: browser, api_only, self_hosted
Constraint provenance is unknown; confirm requirements with the publisher.
Record sources: hashback.dev · github.com. These links do not verify the individual claims.
HashBack is an Auth & identity project. Inferred · not functionally tested: It focuses on authenticating internet-facing services without storing passwords, API tokens, or private keys. Inferred · not functionally tested: HashBack is an open-source project aimed at backend developers and platform engineers. Basis unknown · not verified: HashBack is open source under the MIT license. Basis unknown · not verified: HashBack is available on the web and API, and it can be self-hosted.
billpg.com builds and maintains HashBack, and it first shipped in 2023. The project is developed in the open on GitHub with 93 commits in the last 90 days. Inferred · not functionally tested: Among its 5 catalogued features are secretless authentication, TLS key reuse, and two-request exchange. Inferred · not functionally tested: Catalogued interfaces include a public API.
Summary written by a language model from the project’s public pages.
Tasks: Inferred · not functionally tested
- Secretless authentication
- TLS key reuse
- Two-request exchange
- Server-to-server auth
- HTTPS communication
Topics: Inferred · not functionally tested
Built with & integrations
- Claude Code
- commit 8af704c86b92 · since Sep 2026
Trust & compliance
Indexing history
1What PulseGate has recorded for this listing
- Indexed7 Oct · 12:46 UTCHashBack – Server-to-Server Authentication without secret keys or tokens seen via Hacker News firehose (Algolia)Source: Hacker News firehose (Algolia) · Open
Frequently asked questions about HashBack
- What is HashBack?
- Inferred · not functionally tested: HashBack focuses on authenticating internet-facing services without storing passwords, API tokens, or private keys. It is catalogued under Auth & identity on PulseGate.
- Who is HashBack for?
- Inferred · not functionally tested: HashBack is an open-source project built for backend developers and platform engineers.
- Is HashBack free?
- Basis unknown · not verified: Yes — HashBack is open source under the MIT license and free to use.
- What platforms does HashBack run on?
- Basis unknown · not verified: HashBack runs on the web and API. It can also be self-hosted.
- Is HashBack still maintained?
- PulseGate's liveness check found it on 7 Oct 2026. Its GitHub repository shows 93 commits in the last 90 days.
- What projects are similar to HashBack?
- Similar projects tracked by PulseGate include virt-fido2, EgyDevInfo Sign In with Google, and ClientN Shield.virt-fido2EgyDevInfo Sign In with GoogleClientN Shield
- Who makes HashBack?
- HashBack is developed by billpg.com.
- When did HashBack launch?
- HashBack first shipped in 2023.
Also in Auth & identity
Same category — not a similarity match