# NFID authorization security ensuring

**URL:** <https://forum.dfinity.org/t/nfid-authorization-security-ensuring/30503>\
**Category:** JavaScript\
**Created:** [May 8, 2024, 1:01pm UTC](https://forum.dfinity.org/t/nfid-authorization-security-ensuring/30503 "2024-05-08T13:01:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikita\_TTC](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/nikita_ttc/32/19087_2.png) [@Nikita\_TTC](https://forum.dfinity.org/u/Nikita_TTC)\
**Post date:** [May 8, 2024, 1:01pm UTC](https://forum.dfinity.org/t/nfid-authorization-security-ensuring/30503/1 "2024-05-08T13:01:03Z")

</div>

Hi all! I’m integrating NFID into my project and trying to figure out how I can ensure authorization security.

For the frontend, I use @nfid/embed library.  
Project backend is on PHP.

Currently, I only transfer to my backend the public key and store it there, and then issue an internal session token, but now the public key can be sending from anywehere, including Postman, and anyone can do this as I don’t check if the public key id valid or not.

I’m trying to figure out how I can validate that authorization on the frontend actually happened successfully on the NFID side, and the public key is valid?

There is an idea to encrypt the public key using the signature from the response and OpenSSL, but this is a fallback option, and if possible I’d like to use a native security method.

Thanks for your answers!

---

<div class="post-metadata">

**Author:** ![jennifertran](https://sea1.discourse-cdn.com/flex023/user_avatar/forum.dfinity.org/jennifertran/32/11558_2.png) [@jennifertran](https://forum.dfinity.org/u/jennifertran)\
**Post date:** [May 10, 2024, 12:25am UTC](https://forum.dfinity.org/t/nfid-authorization-security-ensuring/30503/2 "2024-05-10T00:25:06Z")

</div>

I think @dostro and his team can help with this one!

---

<div class="post-metadata">

**Author:** ![olekid](https://avatars.discourse-cdn.com/v4/letter/o/ed8c4c/32.png) [@olekid](https://forum.dfinity.org/u/olekid)\
**Post date:** [May 13, 2024, 12:57pm UTC](https://forum.dfinity.org/t/nfid-authorization-security-ensuring/30503/3 "2024-05-13T12:57:16Z")

</div>

@nfid/embed is frontend library, so it seems you are looking for smth like [https://internetcomputer.org/docs/current/developer-docs/web-apps/independently-verifying-ic-signatures](https://internetcomputer.org/docs/current/developer-docs/web-apps/independently-verifying-ic-signatures), unfortunately there is no php cdk, but u can theoretically use @dfinity/standalone-sig-verifier-web npm package and run js in php
