# 🚀 Announcement: identity.ic0.app & identity.internetcomputer.org → id.ai (Internet Identity 2.0)

**URL:** <https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566>\
**Category:** internet-identity\
**Tags:** nns, internet-identity\
**Created:** [January 13, 2026, 10:44am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566 "2026-01-13T10:44:47Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![aterga](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/aterga/32/4143_2.png) [@aterga](https://forum.dfinity.org/u/aterga)\
**Post date:** [January 13, 2026, 5:02pm UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/21 "2026-01-13T17:02:32Z")

</div>

> [@EdSalazar](#):
>
> is it mandatory to upgrade any frontend currently serving [Internet Identity](https://identity.ic0.app/#authorize) as authentication method or things can be kept as-is?

It is not mandatory to make any changes.

You may keep your entire app as-is.

The suggested changes (i.e., switching to the new id.ai domain) are just a recommendation, and developers may do this either before Jan 26 or after (or decide to never make the switch for whatever reason). However, we do recommend switching, as we’ve observed that some end users associate more trust with the id.ai relative to, e.g., identity.ic0.app.

> [@EdSalazar](#):
>
> A side note: the recovery key verification procedure will be nightmarish to many (pivoting between the copied phrase and the selector for correct ordering). You should consider just allowing people to cut-and-paste what they have copied, which is what you are actually testing for.

Thanks for the feedback. Please note that in id.ai, **even an unverified recovery phrase is active** , i.e., it can be used to recover the respective identity; the UI will just indicate that it hasn’t been verified yet.

I would argue that putting the extra effort into verifying a recovery phrase is worth it for most users, as otherwise those who write their recovery phrase by hand - which id.ai encourages - are risking not being able to recover due to a spelling mistake. Besides, I think I made about 24 clicks (the same number one would need to verify a recovery phrase) just while typing and editing this reply. 🙂

---

<div class="post-metadata">

**Author:** ![EdSalazar](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/edsalazar/32/24584_2.png) [@EdSalazar](https://forum.dfinity.org/u/EdSalazar)\
**Post date:** [January 13, 2026, 6:01pm UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/22 "2026-01-13T18:01:20Z")

</div>

> [@aterga](#):
>
> I would argue that putting the extra effort into verifying a recovery phrase is worth it for most users, as otherwise those who write their recovery phrase by hand - which id.ai encourages - are risking not being able to recover due to a spelling mistake. Besides, I think I made about 24 clicks (the same number one would need to verify a recovery phrase) just while typing and editing this reply. 🙂

😆

Get your point. I’m always thinking of as less friction as possible when dealing with an UX (not the same as when you type an answer: your mind works in a different way even if answering is more complex).

> [@aterga](#):
>
> You may keep your entire app as-is.

Great. Will however try migrate ASAP. Right now

```auto
const identityProvider = (ENV as any).II_URL
    ? String((ENV as any).II_URL)
    : "https://identity.ic0.app/#authorize";

```

so I guess this changes to `https://id.ai` (presume the authentication handshake is now handled directly) hence

```auto
async function loginWithII(authClient: AuthClient): Promise<void> {
  const derivationOrigin =
    (ENV as any).DERIVATION_ORIGIN && String((ENV as any).DERIVATION_ORIGIN).length > 0
      ? String((ENV as any).DERIVATION_ORIGIN)
      : undefined;

  const identityProvider = (ENV as any).II_URL
    ? String((ENV as any).II_URL)
    : "https://id.ai";

  await new Promise<void>((resolve, reject) => {
    authClient.login({
      identityProvider,
      derivationOrigin,
      maxTimeToLive: DELEGATION_MAX_TTL_NS,
      onSuccess: () => resolve(),
      onError: (err) => reject(err),
    });
  });
}

```

While also at `env` level implement

```auto
export const ENV: ICPPEnv = {
   HOST: “https://ic0.app”,
   NETWORK: “ic”,
   II_URL: “https://id.ai”,
   DERIVATION_ORIGIN: “https://tuaah-oaaaa-aaaai-atxxx-yyy.icp0.io”,
}

```

---

<div class="post-metadata">

**Author:** ![sea-snake](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/sea-snake/32/7243_2.png) [@sea-snake](https://forum.dfinity.org/u/sea-snake)\
**Post date:** [January 13, 2026, 6:05pm UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/23 "2026-01-13T18:05:06Z")

</div>

> [@EdSalazar](#):
>
> so I guess this changes to `https://id.ai`

If you want to show extra guidance UX for existing users that have an identity number, I’d recommend to change it to:

```auto
identityProvider: "https://id.ai/?feature_flag_guided_upgrade=true"

```

Feel free to try it with and without the flag to see the difference 😃

---

<div class="post-metadata">

**Author:** ![EdSalazar](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/edsalazar/32/24584_2.png) [@EdSalazar](https://forum.dfinity.org/u/EdSalazar)\
**Post date:** [January 13, 2026, 6:13pm UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/24 "2026-01-13T18:13:58Z")

</div>

Great. Seems sensible advice.

---

<div class="post-metadata">

**Author:** ![EdSalazar](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/edsalazar/32/24584_2.png) [@EdSalazar](https://forum.dfinity.org/u/EdSalazar)\
**Post date:** [January 13, 2026, 6:50pm UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/25 "2026-01-13T18:50:25Z")

</div>

Just implemented the changes. Migrated [https://icpp.tech](https://icpp) and it works perfectly 😉

 ![2026-01-13_19h45_11](https://us1.discourse-cdn.com/flex023/uploads/dfn/original/3X/1/e/1efcb632f45ec51b69d089690158320f92d6b4c9.png)

 ![2026-01-13_19h45_24](https://us1.discourse-cdn.com/flex023/uploads/dfn/original/3X/d/0/d0418b9743f5f1f292dd326d0c16d811a82afdaa.png)

 ![2026-01-13_19h47_30](https://us1.discourse-cdn.com/flex023/uploads/dfn/original/3X/a/1/a155d7f689fc05bef518318046c878b8327b6da2.jpeg)

---

<div class="post-metadata">

**Author:** ![wiyota](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/wiyota/32/27664_2.png) [@wiyota](https://forum.dfinity.org/u/wiyota)\
**Post date:** [January 14, 2026, 4:33am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/26 "2026-01-14T04:33:37Z")

</div>

Is the [`IDENTITY_PROVIDER_DEFAULT`](https://github.com/dfinity/icp-js-auth/blob/2a6f2a5c5e48d315288de74aee0e120bdeeb8382/src/client/auth-client.ts#L34C7-L34C32) in the [`@icp-sdk/auth`](https://github.com/dfinity/icp-js-auth) library also scheduled to be changed to `https://id.ai` (or the version with a feature flag) around Jan 26?

I plan to update the default identity provider URL in [`ic-auth-client-rs`](https://github.com/wiyota/ic-auth-client-rs) in synchronization with the JS SDK.

---

<div class="post-metadata">

**Author:** ![SmartMonkey](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/smartmonkey/32/30675_2.png) [@SmartMonkey](https://forum.dfinity.org/u/SmartMonkey)\
**Post date:** [January 14, 2026, 5:10am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/27 "2026-01-14T05:10:25Z")

</div>

I’ve upgraded my identity. On my phone now i have the old nns app and the new id.ai app. My question is am I going to have the same functionality in Id.ai as in the old nns.app, meaning the staking, voting etc… etc… or the internet identity 2.0 is only for logging in to apps?

---

<div class="post-metadata">

**Author:** ![yk6](https://avatars.discourse-cdn.com/v4/letter/y/b2d939/32.png) [@yk6](https://forum.dfinity.org/u/yk6)\
**Post date:** [January 14, 2026, 5:38am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/28 "2026-01-14T05:38:49Z")

</div>

Just wanna keep my II1.0 🙂

---

<div class="post-metadata">

**Author:** ![ic.aitubi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/ic.aitubi/32/14179_2.png) [@ic.aitubi](https://forum.dfinity.org/u/ic.aitubi)\
**Post date:** [January 14, 2026, 7:53am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/29 "2026-01-14T07:53:54Z")

</div>

Hi @aterga, thanks for your guidance. With the help of @quint - and a bit of chatgpt - I sorted out the upgrade.  
_IN SUMMARY_

1. Go to [https://id.ai/](https://id.ai/)
2. Sign in, top right of screen
3. Select “Use another identity”
4. Select: “Continue with passkey”
5. Select “Upgrade” bottom right
6. Menu appears “Upgrade your existing identity to the new experience in two steps
7. Enter anchor number of Internet Identity 1.0, hit “Continue”  
_DONE_

I notice that my old 1.0 and new 2.0 now simply co-exist and I understand that they are additive, meaning 2.0 is linked to, does not replace the legacy 1.0.  
NNS and OISY seem to also keep using my old 1.0 anchor only. That is fine. The well functioning of both is my current main focus to secure my assets.  
**Hence my remaining questions**

1/ Will NNS and OISY for now continue to use the old 1.0 II only and how/when will they migrate?  
2/ Since II 2.0 does not yet support Ledger HW can you guarantee that access to my NNS account secured by a Ledger HW wallet will continue to function flawlessly?

---

<div class="post-metadata">

**Author:** ![b3hr4d](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/b3hr4d/32/9755_2.png) [@b3hr4d](https://forum.dfinity.org/u/b3hr4d)\
**Post date:** [January 14, 2026, 8:31am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/30 "2026-01-14T08:31:47Z")

</div>

Hey folks! 👋

With everyone upgrading to **Internet Identity 2.0 / id.ai** , now’s a great moment to simplify your frontend auth + data fetching.

If you’re building with **React** , **ic-reactor v3** makes login **ridiculously easy** thanks to `createAuthHooks` — it handles session restore, the II popup, agent updates, and reactive state **behind the scenes**. You basically just call `login()` when the user clicks, and everything works.

### Quick Installation (important: include auth package!)

```bash
npm add @ic-reactor/react@beta @icp-sdk/core @icp-sdk/auth @tanstack/react-query
# or pnpm / yarn equivalents

```

### Super Simple Setup

1. Create your `ClientManager` (one time, e.g. in a context/provider file):

```ts
// clientManager.ts
import { ClientManager } from "@ic-reactor/core";
import { QueryClient } from "@tanstack/react-query";

export const queryClient = new QueryClient();

export const clientManager = new ClientManager({
  queryClient,
  // Optional: try the new experimental feature for automatic env detection!
  // Great for @icp-sdk toolchain / icp-cli dev servers (reads ic_env cookie)
  // ⚠️ Experimental — may have issues with localhost update calls
  // withCanisterEnv: true,
  // Or use: withProcessEnv: true // classic dfx / env vars detection
});

```

1. Generate auth hooks:

```ts
// authHooks.ts
import { createAuthHooks } from "@ic-reactor/react";
import { clientManager } from "./clientManager";

export const { useAuth, useUserPrincipal, useAgentState } = createAuthHooks(clientManager);

```

1. In your component:

```tsx
import { useAuth } from "./authHooks";

function LoginButton() {
  const { login, logout, isAuthenticated, identity, isAuthenticating } = useAuth();

  if (isAuthenticating) return <div>Signing in...</div>;

  if (isAuthenticated) {
    return (
      <div>
        Welcome {identity?.getPrincipal().toText().slice(0, 8)}...!
        <button onClick={logout}>Logout</button>
      </div>
    );
  }

  return (
    <button
      onClick={() => login({
        // Default to `https://id.ai` For already live apps with legacy II users:
        identityProvider: "https://id.ai/?feature_flag_guided_upgrade=true"
      })}
    >
      Login with Internet Identity
    </button>
  );
}

```

The `useAuth()` call automatically:

- Restores existing session on mount
- Switches to authenticated agent
- Keeps TanStack Query in sync (invalidates on identity change)

**Bonus mention:** the new `withCanisterEnv: true` option (experimental) auto-detects your dev environment from the `ic_env` cookie when using modern `@icp-sdk` tools/icp-cli — super handy for seamless staging ↔ mainnet switching without manual host config. Just be cautious on localhost update calls for now.

Saves **tons** of boilerplate compared to raw actors.

Try it out during this II 2.0 wave — feedback very welcome!

🔗 Full announcement & docs: [[v3 Beta Announcement] IC Reactor: The "Missing" Data-Fetching Library for Internet Computer](https://forum.dfinity.org/t/v3-beta-announcement-ic-reactor-the-missing-data-fetching-library-for-internet-computer/62164)  
ClientManager ref: [ClientManager | IC Reactor](https://b3pay.github.io/ic-reactor/v3/reference/clientmanager/)  
Auth hooks overview: [createAuthHooks | IC Reactor](https://b3pay.github.io/ic-reactor/v3/reference/createauthhooks/overview/)

Happy coding & smooth upgrades! 🚀

---

<div class="post-metadata">

**Author:** ![jonit](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/jonit/32/12279_2.png) [@jonit](https://forum.dfinity.org/u/jonit)\
**Post date:** [January 14, 2026, 10:31am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/31 "2026-01-14T10:31:12Z")

</div>

Is there a page online that goes through the process for users and one separate one for apps?  
I’m still not clear on what I need to do as a user as the posts are usually intertwined with information about apps.

---

<div class="post-metadata">

**Author:** ![sea-snake](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/sea-snake/32/7243_2.png) [@sea-snake](https://forum.dfinity.org/u/sea-snake)\
**Post date:** [January 14, 2026, 12:48pm UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/32 "2026-01-14T12:48:01Z")

</div>

> [@wiyota](#):
>
> s the [`IDENTITY_PROVIDER_DEFAULT`](https://github.com/dfinity/icp-js-auth/blob/2a6f2a5c5e48d315288de74aee0e120bdeeb8382/src/client/auth-client.ts#L34C7-L34C32) in the [`@icp-sdk/auth`](https://github.com/dfinity/icp-js-auth) library also scheduled to be changed to `https://id.ai` (or the version with a feature flag) around Jan 26?

We will update the library a bit later after the 26th since we want people to explicitly switch the guided flow (not implicitly by updating a library).

> [@SmartMonkey](#):
>
> am I going to have the same functionality in Id.ai as in the old nns.app, meaning the staking, voting

Yes, when you sign into the NNS through id.ai (instead of identity.ic0.app), you’ll have the same NNS functionality as before.

> [@ic.aitubi](#):
>
> Will NNS and OISY for now continue to use the old 1.0 II only and how/when will they migrate?

They’ll also migrate at the latest on January 26th.

> [@ic.aitubi](#):
>
> Since II 2.0 does not yet support Ledger HW can you guarantee that access to my NNS account secured by a Ledger HW wallet will continue to function flawlessly?

> [@sea-snake](#):
>
> Yes, though if you’re using the ledger HW wallet as a passkey with II, you’ll need to create a new passkey using another method during the upgrade since the ledger HW wallet does not support discoverable passkeys at this moment.
> 
> [https://identitysupport.dfinity.org/hc/en-us/articles/40276570234132-Internet-Identity-upgrade-FAQ#:~:text=Confirmed%20to%20have%20issues%20with%20Internet%20Identity%202.0%3A](https://identitysupport.dfinity.org/hc/en-us/articles/40276570234132-Internet-Identity-upgrade-FAQ#:~:text=Confirmed%20to%20have%20issues%20with%20Internet%20Identity%202.0%3A)
> 
> [https://support.ledger.com/article/12350325732893-zd#:~:text=Does%20the%20Security%20Key%20app%20support%20resident%20keys%3F](https://support.ledger.com/article/12350325732893-zd#:~:text=Does%20the%20Security%20Key%20app%20support%20resident%20keys%3F)
> 
> Regarding using a ledger HW wallet in the NNS directly, this remains unchanged.

---

<div class="post-metadata">

**Author:** ![ICP2025](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@ICP2025](https://forum.dfinity.org/u/ICP2025)\
**Post date:** [January 15, 2026, 12:47am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/33 "2026-01-15T00:47:22Z")

</div>

PLEASE add locking and unlocking seed phrases ASAP. The flaw with ii2 is that if someone dropped their security key on the street, without even knowing their anchor number, an attacker could simply go on id.ai and hold the security key up to their device and have full access, AND RESET THE SEED PHRASE. Forcing users to upgrade to access their NNS Wallets without even having lockable seed phrases is not right, and needs to be addressed before it becomes forced on users!!!

---

<div class="post-metadata">

**Author:** ![ICP2025](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@ICP2025](https://forum.dfinity.org/u/ICP2025)\
**Post date:** [January 15, 2026, 12:57am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/34 "2026-01-15T00:57:18Z")

</div>

Not to mention, if someone’s icloud, google, or microsoft accounts get compromised, the attacker can again instantly reset the phrase. We need a hot fix for this like the one password proposal ASAP 🙏

---

<div class="post-metadata">

**Author:** ![yk6](https://avatars.discourse-cdn.com/v4/letter/y/b2d939/32.png) [@yk6](https://forum.dfinity.org/u/yk6)\
**Post date:** [January 15, 2026, 1:23am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/36 "2026-01-15T01:23:47Z")

</div>

Anchor number+seed phrase=perfect store method

---

<div class="post-metadata">

**Author:** ![ICP2025](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@ICP2025](https://forum.dfinity.org/u/ICP2025)\
**Post date:** [January 15, 2026, 1:59am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/37 "2026-01-15T01:59:55Z")

</div>

Yeah, sucks that they are removing the anchor number and making it so that you can no longer lock your seed phrase (making it so that it can be reset with simple access to the account)

---

<div class="post-metadata">

**Author:** ![yk6](https://avatars.discourse-cdn.com/v4/letter/y/b2d939/32.png) [@yk6](https://forum.dfinity.org/u/yk6)\
**Post date:** [January 15, 2026, 2:15am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/38 "2026-01-15T02:15:42Z")

</div>

Anchor number are still used on backend, but hidden from users.

anyway, its a pity to remove anchor numbers and force users upgrade to II2.

---

<div class="post-metadata">

**Author:** ![ic.aitubi](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/ic.aitubi/32/14179_2.png) [@ic.aitubi](https://forum.dfinity.org/u/ic.aitubi)\
**Post date:** [January 15, 2026, 8:30am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/39 "2026-01-15T08:30:58Z")

</div>

When logging into my NNS wallet using II 1.0, I do not require the HW wallet, just to view all assets and even vote on neurons. The HW wallet is required when moving assets, or similar actions like disbursing etc.  
My understanding is this means that I am NOT using the ledger HW wallet as passkey with II.  
So is my correct path of action as follows?

1. upgrade to II 2.0;
2. continue using II 1.0 to log into NNS till Jan 26th, automatically switch over to 2.0 after that for NNS login;
3. once logged into NNS, at all times interaction with HW wallet remains unchanged.

---

<div class="post-metadata">

**Author:** ![sea-snake](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/sea-snake/32/7243_2.png) [@sea-snake](https://forum.dfinity.org/u/sea-snake)\
**Post date:** [January 15, 2026, 8:34am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/40 "2026-01-15T08:34:56Z")

</div>

> [@ic.aitubi](#):
>
> My understanding is this means that I am NOT using the ledger HW wallet as passkey with II.  
> So is my correct path of action as follows?
> 
> 1. upgrade to II 2.0;
> 2. continue using II 1.0 to log into NNS till Jan 26th, automatically switch over to 2.0 after that for NNS login;
> 3. once logged into NNS, at all times interaction with HW wallet remains unchanged.

That’s indeed correct.

---

<div class="post-metadata">

**Author:** ![ICP2025](https://avatars.discourse-cdn.com/v4/letter/i/b77776/32.png) [@ICP2025](https://forum.dfinity.org/u/ICP2025)\
**Post date:** [January 15, 2026, 9:43am UTC](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566/41 "2026-01-15T09:43:34Z")

</div>

Sea snake will you please reply to my post about locking seed phrases? I am extremely concerned for the security of my funds as a result of the new update. Thanks.

[Previous page](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566.md?page=1)

[Next page](https://forum.dfinity.org/t/announcement-identity-ic0-app-identity-internetcomputer-org-id-ai-internet-identity-2-0/62566.md?page=3)
