Passwordless authentication lets a user sign in without a password, instead using a method such as a passkey, a one-time code sent by email or SMS, a magic link, or a hardware security key. It removes the most commonly attacked credential (the reusable password) while typically reducing sign-in friction.
Frequently asked questions
Is passwordless authentication less secure than a password?
Generally more secure, since it removes the risk of reused, guessed, or phished passwords, particularly with phishing-resistant options like passkeys.
What's the easiest passwordless method to roll out?
Magic links and one-time codes require the least customer education, while passkeys offer the strongest security but depend on device support.
How is this different from passkeys specifically?
Passwordless authentication is the general category; passkeys are one specific, phishing-resistant implementation of it. See passkeys.
.avif)