·HUMAN SESSIONS
Passwordless,
by default.
Passkeys, magic links, OAuth, SAML. Every modern auth method, one API. Your users stop memorizing passwords. You stop reporting breaches.
The last password you'll ever ship
Every password is a future breach.
The average human reuses six passwords across their digital life. Passkeys end that.
01
Passkeys, first-class.
WebAuthn with FIDO2 is the default. Touch ID, Face ID, and Windows Hello all work through one API. Magic link is the fallback when the platform can't do biometrics.
02
Every OAuth provider, ready.
27 providers pre-wired. Google, GitHub, Apple, Microsoft, LinkedIn, Discord, Slack, plus regional players. One adapter interface to add your own in 40 lines.
03
Session rotation you don't think about.
Cookies rotate on privilege change, IP jump, or stale inactivity. CSRF double-submit out of the box. Revocation propagates edge-wide in under 500ms.
04
MFA and recovery that don't suck.
TOTP, WebAuthn as second factor, SMS for last-resort recovery. Codes hashed like passwords with Argon2id. Impersonation guards prevent admin-panel account takeover.
Ship real auth this afternoon.
Install the library. Wire your adapter. Your users stop thinking about passwords.
MIT licensed · TypeScript · Edge-native · Zero dependencies