The next useful thing.
Ship a working loop. Improve the parts people actually use.
v0: make one flow work
A visitor starts at a site, completes hosted voice entry, returns through a checked callback, and reaches a protected page. The public site and integration example must point to real destinations. Credentials stay server-side, sessions and moderation are enforced on the server, and no private data ships in the repository. Broken entry, callback, or access control blocks v0; broader research does not.
v1, in priority order
- Reliable phone entry. Resolve the observed iPhone phrase failure and verify complete iPhone and Android journeys.
- Recognition across visits and devices. Measure false matches, missed returners, duplicate creation, and abandonment with consenting participants.
- Recovery and usable moderation. Give uncertain visitors a clear next step and site owners an understandable, bounded moderation workflow.
- Measured service capacity. Exercise the deployed host under realistic traffic; publish load, latency, and failure behavior.
- Less integration work. Improve registered-client setup, key changes, documentation, and runnable examples from operator feedback.
- Evaluate stronger origin checks. Assess spoof resistance separately before strengthening any human-presence claim.
Later, if the evidence supports it
Standard OAuth/OIDC interoperability and wider deployment options. Dates and performance promises will follow working evidence, not precede it.