Account linking
Users who sign in with a second provider land on the same account instead of a duplicate.
- Deterministic linking by verified email
- Multiple identities per user record
- No duplicate accounts to reconcile
Authentication
Ship sign-in that converts and holds up to scrutiny: social SSO, passwordless, MFA, and enterprise connections from a single integration.
Social SSO
Let users arrive with an account they already have. Providers are configured per environment, with account linking handled for you.
Connect Google, GitHub, Microsoft, Apple, and more from the console, with no provider-specific code in your app.
Users who sign in with a second provider land on the same account instead of a duplicate.
Offer SAML and OIDC connections to customer IT teams without a separate integration.
Username and password, social login, SSO, and passwordless all resolve to the same session and token model.
Multi-factor authentication
Layer a second factor onto any sign-in method, with enrollment and recovery flows handled for you.
One-time codes delivered through your configured messaging and email providers.
TOTP enrollment for any authenticator, with QR provisioning built into the hosted flows.
WebAuthn security keys for the phishing-resistant tier your enterprise buyers ask about.
Recovery codes and admin-assisted flows so a lost factor is not a lost account.
Passwordless
Remove the password from the critical path with passkeys, magic links, and one-time codes.
WebAuthn passkeys for phishing-resistant sign-in that users never have to remember.
Single-use sign-in links delivered through your own email provider and domain.
Short numeric codes for flows where a link is awkward, such as native and TV apps.
Console and compliance
Configure providers, inspect what happened, and prove it later, without shipping a release.
Providers, policies, branding, and claims are scoped to each environment, so staging never leaks into production.
Every authentication event recorded with actor, method, and outcome for security review.
Search users, inspect sessions and devices, and revoke access from one place.
Embeddable components
Drop in prebuilt flows and account UI, or drive the same APIs from your own components.
A complete sign-up flow with the methods you enabled, validation, and verification built in.
Sign-in with social providers, passwordless, MFA challenges, and enterprise routing handled.
Self-service profile, security settings, connected accounts, and session management.
Install one SDK or point your app at the hosted sign-in pages.
Enable the methods, providers, and factors you want per environment.
Go live with sessions, tokens, and audit logs at the edge.
Open the console to configure providers, policies, and environments in one place.