LINKSPREED Announces UIID Wrap — Sign In and Create Accounts Anywhere, With the User Always in Control
LINKSPREED announces UIID Wrap, a capability that prepares and fills account registrations, generates privacy-preserving account data, and binds the resulting account to a UIID alias, with the user remaining the acting party for every decision that matters.
United States, September 28, 2026 — LINKSPREED today announced UIID Wrap, a newly announced capability that extends UIID to websites that have not integrated it. UIID Wrap prepares and fills account registrations, generates privacy-preserving account data, and binds the resulting account to a UIID alias — while the user remains the acting party for every decision that matters.
This is a new announced project and will be worked on in upcoming releases.
More about UIID at uiid.me.
The problem
Users create platform-specific accounts constantly. Each time, they disclose more data than the service actually needs, invent another username, set up another recovery channel, and then lose track of where that identity exists at all.
Native UIID adoption cannot fix this immediately, because most websites will not integrate a new identity provider on day one. UIID Wrap is the bridge across that gap: it makes UIID useful on the web as it exists today, while building the path to native federated login as adoption grows.
The core principle: UIID prepares, the user decides
This is the design decision that defines the product, and we are stating it first because everything else follows from it.
UIID supplies the identity and prepares the account. The user creates the account through an informed and explicit action.
UIID Wrap detects the registration flow, generates privacy-preserving account data, fills the site’s native form, and presents the relevant terms and information for review. The user reviews it, handles any required challenge, and performs the final submission themselves on the website.
This preserves almost all of the convenience of a one-click experience while keeping the person — not the software — as the party who agrees to anything. Fully automatic account creation is reserved for contracted partner integrations, where the platform has explicitly agreed to it.

How it works
- Detection. UIID Wrap detects a login or registration interface in the active browser tab.
- Identity selection. The user chooses their Core ID, an existing alias, or creates a new alias specifically for this website.
- Generation. UIID generates the minimum required account data: a site-specific username, a relay email address and a strong credential.
- Filling. UIID fills the compatible fields in the website’s own native registration form.
- Review. The user reviews the supplied data alongside the site’s terms, privacy notice and any declarations.
- Submission. The user performs the final submission using the website’s own control.
- Binding. After success, UIID offers to link the resulting account to the chosen alias and stores the credential material securely.
- Later. On subsequent visits, UIID offers a user-authorized login — or migration to native UIID federation if the platform adopts UIID.
Three operating modes
| Mode | When it applies | Who creates the account |
|---|---|---|
| Native Provisioning | Contracted UIID partners | The platform creates the account through an approved API after UIID approval — a genuine one-click flow, because the partner authorized it |
| Assisted Registration | Compatible non-integrated websites | UIID fills the native form; the user reviews and submits |
| Manual Fallback | Unknown or incompatible websites | UIID generates credentials only; the user copies approved values manually |
Unknown websites start in manual fallback. Assisted mode is activated only after a reviewed compatibility record exists for that origin.
What UIID Wrap will never do
We think a product that touches account creation should publish its limits before it ships, not after someone discovers them. UIID Wrap is built so that the following are structurally impossible:
- No CAPTCHA solving and no anti-bot bypass. Challenges are completed by the user, always.
- No invented legal name, address, date of birth, phone number or identity evidence. UIID never fabricates a fact about a person.
- No automatic selection of marketing consent. Ever, by default or otherwise.
- No silent acceptance of terms or privacy notices. Contractual confirmation is a user action.
- No background account creation while the user is not actively present.
- No creation of multiple accounts where the service prohibits it, and no circumvention of suspensions, bans or account limits.
- No implication of partnership. A site is never presented as a UIID partner unless a partnership actually exists.

Why this is more than a password manager
| Capability | Password manager | UIID Wrap |
|---|---|---|
| Identity model | One general vault | Core ID plus isolated, disposable aliases |
| Registration | Usually saves what the user typed | Generates a data-minimized platform identity and prepares the account |
| Lifecycle | Edit or delete a credential | Pause, archive or purge an entire identity context |
| Privacy | Stores credentials | Controls which identity facts are exposed per platform |
| Audit | Login history, varies by product | Cross-platform identity audit tied to the Core ID or alias |
| Migration | No identity migration path | Retires the legacy credential when native UIID login becomes available |
The practical difference is compartmentalization. Because each linked account belongs to a context rather than to one undifferentiated vault, purging an alias removes an entire slice of the user’s digital footprint in a single action — every account, every relay address, every credential bound to that context. No conventional credential manager offers that, because no conventional credential manager has an identity model underneath it.
Security architecture
- Extension-owned interface. Sensitive UI renders in a surface the website cannot imitate, inspect or overlay. Decrypted credentials are never exposed to page JavaScript, to logs or to remote telemetry.
- Isolated execution. Content scripts run in an isolated world and receive only the minimum data needed for the active form.
- Strict origin matching, including defenses against lookalike and internationalized-domain attacks. A credential is never released across origins — which is what makes phishing against Wrap structurally hard rather than merely discouraged.
- Encryption before synchronization. Credentials are encrypted on the device. The server holds ciphertext or references, never plaintext. Passwords, passkey private keys, verification tokens, session cookies and recovery codes are never stored in plaintext anywhere.
- Re-authentication for sensitive operations — revealing, exporting, reassigning an alias or performing bulk operations.
- Relay email addresses can be disabled independently, so a user can cut off one site’s access to their inbox without touching anything else.
Governed, not generic
UIID Wrap uses a signed website compatibility registry. Each record describes exactly what UIID is permitted to do for a specific origin — which fields may be filled, which are restricted, and what must always remain a user action — together with the date it was last reviewed.
Material changes to a website’s registration flow trigger re-review, and an emergency control allows a domain to be disabled immediately without waiting for an extension update. This is what converts a generic automation feature into a governed product with a named owner for every rule.
On the browser extension
We will be straightforward about a constraint: a full Wrap experience on arbitrary third-party sites requires an installed client. Reading and modifying another site’s pages is exactly what the browser’s security model is designed to prevent, and there is no supported mechanism by which visiting one website grants capability that then runs on unrelated websites. Such a mechanism would itself be a critical vulnerability, and we are not interested in products that depend on one.
What does not require an extension: sites that integrate UIID can detect an existing session silently, and where the browser supports browser-mediated federation, UIID can appear as a native sign-in option without redirects or third-party cookies. That mechanism is available in Chromium-based browsers and under development elsewhere, so a redirect fallback remains part of the design for the foreseeable future.
Accessibility and transparency requirements
- Every action is keyboard-accessible and screen-reader labeled.
- The interface visibly distinguishes generated values from verified identity facts.
- Users can edit any value before it is filled.
- Where a field cannot be automated, the extension explains why rather than failing silently.
- A privacy view shows exactly what the website receives and exactly what UIID stores.
Availability
UIID Wrap is a newly announced project and will be delivered in upcoming releases, beginning with a pilot on a small, reviewed set of domains while native provisioning is developed for contracted partners.
Announcements will be published through LINKSPREED’s press channel, at blog.linkspreed.com and in the Help Center at help.linkspreed.com.
Users and platform operators interested in early access can apply to the Trusted Tester Program by emailing [email protected], naming UIID Wrap and including their UIID. Applications without a UIID are not evaluated.
About LINKSPREED
LINKSPREED is the company behind UIID, a universal digital identity platform providing standards-based, passwordless identity for people, organizations, software agents and machines, and the broader Web4 ecosystem.
Learn more at uiid.me.