cryptographic authentication for physical things

Tap the thing.
Verify the connection.

Watermelon Auth turns secure NFC tags into cryptographically authenticated credentials for people, products, specimens, assets, and documents. A phone tap produces a fresh cryptographic response that the issuer can verify in real time.

People. Products. Specimens. Assets. Documents.

A phone taps a physical object and the screen shows: Authentic, fresh tap. Credential RM-0001-A, status active, issued by Richard's Minerals.

product

Stronger than a QR code. More practical than enterprise credential infrastructure.

01

Fresh proof

Every real tap produces a new cryptographic response from the physical credential. A copied link, QR code, photograph, or screenshot cannot.

02

Issuer controlled

You manage the credential, its status, the cryptographic keys, and the verification policy. Nothing works without your tenant's server-side state.

03

White-label

Your domain, your branding, your terminology, your verification experience. Watermelon Auth runs underneath.

the gap

Physical identity should be harder to copy.

Static identifiers

QR codes, printed numbers, barcodes, and ordinary NFC tags can be photographed, reproduced, forwarded, or imitated.

Enterprise systems

Strong credential infrastructure often requires proprietary readers, closed platforms, and heavy integration.

Watermelon Auth

Secure, phone-native, issuer-controlled physical authentication. Stronger than static; far more practical than enterprise.

how it works

Six steps from blank tag to verified thing.

1

Issue

Create the identity and the credential record, with policy and status.

2

Provision

Securely personalize the NFC tag with card-specific derived keys.

3

Attach

Associate the credential with the physical thing.

4

Tap

A phone receives a fresh dynamic response from the secure tag.

5

Verify

The server validates the cryptography, counter, and credential state.

6

Present

Show the branded result, context, and provenance.

The tap is the test. A screenshot, photo, QR copy, or forwarded link is not a tap โ€” only the physical credential produces the fresh response the verifier accepts.
use cases

Who is it for?

An identity does not have to be a person. The architecture is deliberately generic.

Schools

Student and staff IDs without enterprise access-control overhead.

Memberships

Club cards, event passes, association credentials with live status checks.

Products

Tap the item and reach the issuer's authenticated record.

Specimens & collectibles

Authentication combined with provenance, photos, and custody history.

Assets & equipment

Managed credential records instead of a printed asset number.

Documents

Authenticated physical seals and records.

provisioning

An Android app writes the cards.

Watermelon Auth includes a purpose-built Android provisioner. It personalizes blank NTAG 424 DNA tags with secure settings and card-specific derived keys โ€” the same cryptographic machinery the verification side relies on.

How provisioning works

The provisioner authenticates to the tag with EV2, configures its secure access conditions, and writes the credential using keys derived per card from the tenant's master keyset.

The tenant master keys stay on the server. The app works with already-derived card-specific keys โ€” the high-value secret never enters the phone.

What ships today

The Android app is a real, field-tested component: EV2 authentication, secure messaging, SDM setup, and key diversification are done and proven on physical hardware.

The app currently receives provisioning bundles through a local workflow (ADB / intent extras from the operator's machine). An app-to-server provisioning API is the next milestone.

Tenant-isolated keys. Each organization controls its own credential boundary โ€” and the Android app never holds the master secret, only the derived keys for the cards it is writing.
provenance

Authentication tells you what you tapped. Provenance tells you what is recorded about it.

Authentication answers: did I tap a valid credential?

Fresh cryptographic response, counter progression, credential state โ€” verified server-side, in real time.

Provenance answers: what do we know about the thing attached to it?

Append-only records, photographs, source attribution, ownership history, and integrity-linked entries โ€” connected to the physical object.

The physical thing carries the credential. The platform carries the trusted context.

platform

One platform. Many issuers.

Multi-tenant by design

Each organization has its own domain, branding, credential namespace, terminology, and cryptographic boundary.

A school shows Freedom Academy Credential Verification. A mineral collection shows Richard's Minerals. A manufacturer shows its own product authentication. One platform, separate trust.

Add authentication without replacing your application

Watermelon Auth verifies the credential. Your application remains the source of business data.

Authenticate the physical object, then hand the verified identity to your existing product database, inventory system, or portal.

security

Precise about what is proven.

Watermelon Auth proves what the cryptography supports โ€” and says so. That precision is part of the product.

What the platform provides

  • cryptographically authenticated credentials
  • secure NFC credential technology
  • fresh dynamic responses per tap
  • diversified, per-card derived keys
  • replay-aware verification
  • tenant-specific key isolation
  • issuer-controlled credential state

What the platform does not claim

  • impossible to clone
  • unhackable
  • impossible to counterfeit
  • guaranteed authentic physical object
  • tamper-proof
live implementation

This is not a design proposal. It is running now.

The reference implementation runs at verify.melon.tips, showing the provenance side through Richard's Minerals โ€” a mineral collection where each specimen carries a secure NFC credential connected to its digital record.

Try the demo credential: RM-0001-A. A bare link cannot stand in for a tap โ€” the verifier requires the fresh cryptographic response the tag produces, and refuses anything else.

The tap is the test.

Turn physical things into trusted digital experiences. Issue it. Verify it. Revoke it. Replace it. Audit it.