Passport
Identity, handled

Passport is the identity layer for modern apps — login, MFA, sessions, SSO, and org management behind one API. Issue your first token in five minutes and hand the breach liability to a team that does nothing else.

  • Free up to 10,000 monthly active users
  • SOC 2 Type II + ISO 27001
  • 31ms median token verify
Overview
Live
$2.4M
Volume
+18.2%
Growth
99.99%
Uptime

The identity layer behind teams that can't afford a leaked password

NorthwindCobalt HealthDriftpayLumen RoboticsTidal BankMeridian Labs
The platform

Every way a userproves who they are,in one API.

Stop wiring together a password hasher, an email provider, a TOTP library, and a half-finished SSO flow. Passport ships the entire identity surface so your roadmap goes back to being about your product.

Login that just works

Email-and-password, magic links, passkeys, and 30+ social and enterprise providers behind one consistent flow. Argon2id hashing, every signup screened against billions of leaked credentials, and a hosted login page you can theme to pixel parity — or rebuild headless against the API.

MFA that doesn't annoy

TOTP, SMS, email codes, and WebAuthn passkeys with adaptive step-up — challenge the risky login, wave through the one from a known device on a known network.

Sessions, done right

Rotating refresh tokens, httpOnly cookies, per-device tracking, and instant revocation. Kill a stolen session across every device in a single call.

Enterprise SSO on tap

SAML and OIDC for any customer's IdP — Okta, Entra, Google Workspace — configured in an afternoon instead of a six-week integration project.

Users & orgs out of the box

Multi-tenant orgs, roles, invites, and a fine-grained permission model, so your B2B customers run their own teams without filing a ticket against your engineers.

Numbers that hold up under load

31ms
Median token verify, at the edge
99.99%
Auth uptime, multi-region SLA
11B+
Breached credentials screened
190+
Countries served on day one
Built for developers

An auth APIyou won't fight.

Typed end to end, idempotent by default, and documented like a product. The integration that used to eat a sprint now fits between standup and lunch.

Five-minute quickstart

Drop in an SDK, paste two keys, and your first user signs up. The hosted flow renders the screens; the API handles tokens, hashing, and rotation.

Typed SDKs everywhere

First-class libraries for TypeScript, Python, Go, Ruby, and Rust — fully typed, with framework adapters for Next.js, Express, and FastAPI.

Standards, not lock-in

Plain OAuth 2.1 and OpenID Connect under the hood. Verify JWTs against our JWKS yourself, or export every user and credential the day you decide to leave.

Webhooks that retry

Guaranteed-delivery events for every signup, login, and revocation — signed payloads, exponential-backoff retries, and a replay console for the ones you missed.

Threat model

The attacks you stop owning the day you switch.

Most auth breaches aren't exotic — they're the same handful of failures shipped by a team that builds login once and never revisits it. Passport closes them by default, patched the moment the technique changes, not the next time you remember to look.

OWASP A07

Credential stuffing

Every signup and reset is checked against 11B+ leaked passwords, and brute-force attempts hit per-IP and per-account rate limits before they reach your database.

Adaptive MFA

Account takeover

A login from a new device, country, or impossible-travel path triggers step-up automatically. The attacker has the password; they still can't get in.

Token rotation

Session hijacking

Refresh tokens rotate on every use and a replayed token invalidates the chain, so a stolen cookie is dead the moment the real user comes back.

WebAuthn passkeys

Phishing

Passkeys are cryptographically bound to your origin — a credential phished on a look-alike domain is mathematically useless to the attacker.

Scoped tokens

Privilege escalation

Fine-grained roles and short-lived, audience-scoped tokens mean a compromised low-privilege session can't quietly become an admin one.

Immutable logs

Insider & audit gaps

Every auth event — login, grant, revocation, role change — lands in a tamper-evident log you can hand straight to an assessor or a forensics team.

From the engineers

Teams that deleted their auth code sleep better.

We deleted 14,000 lines of auth code and shipped enterprise SSO in a single afternoon. The first customer who asked for SAML had it the same day instead of next quarter.

P
Priya Nair
Staff Engineer, Driftpay

Our security review used to stall every enterprise deal. Now we hand over Passport's SOC 2 report and the audit checklist closes itself. It unblocked two seven-figure contracts in a quarter.

M
Marcus Whitfield
CTO, Tidal Bank

A reused password got flagged and adaptive MFA stopped the takeover before it touched a single account. That one catch paid for the whole platform on day one.

D
Devon Clarke
Head of Platform, Lumen Robotics
Pricing

Free until you're real. Then priced per user.

No charge for the users who never come back. You pay for monthly active users, and enterprise SSO is never paywalled behind a sales call that hides the number.

Free

For prototypes and early products finding their footing.

$0/mo
  • Up to 10,000 monthly active users
  • Passwords, magic links & passkeys
  • TOTP & email MFA
  • Hosted login page
  • Community support
Most popular

Growth

For products with real users and real customers.

$0.02/MAU
  • Volume pricing past 10k MAU
  • Enterprise SSO (SAML + OIDC)
  • Adaptive MFA & risk engine
  • Multi-tenant orgs & roles
  • Webhooks & 90-day logs
  • Priority support

Enterprise

For regulated, high-volume, multi-region platforms.

Custom
  • Unlimited MAU & custom pricing
  • Data residency & single-tenant
  • HIPAA BAA + audit logging
  • 99.99% uptime SLA
  • SCIM provisioning & DPA
  • Named solutions engineer

Straight answers for engineers.

How long does integration actually take?

Most teams have signup, login, and MFA working in well under an hour using a typed SDK and the hosted login page. Enterprise SSO for a specific customer is typically live the same day — you configure their IdP, you don't rebuild your stack.

Can I migrate off another provider — or off Passport?

Both directions, with zero downtime. Our importer ingests users and password hashes from Auth0, Cognito, Firebase, or your own database without forcing a reset, and you can export every user and credential at any time. No walled garden.

Is Passport compliant enough for our security review?

Passport is SOC 2 Type II and ISO 27001 certified, supports HIPAA BAAs and immutable audit logs, and offers data residency by region. We hand auditors a report instead of a maybe.

Hosted login or fully headless?

Your choice. Use the hosted Universal Login for the fastest, safest path, or build entirely against the API and SDKs for pixel-perfect control. You can start hosted and go headless later without re-platforming.

What happens if Passport goes down?

We run a 99.99% uptime SLA across multiple regions with automatic failover, and tokens validate at the edge against cached JWKS, so verification keeps working through transient blips. Status and incident history are public.

Do you support passkeys and passwordless?

Yes — WebAuthn passkeys are first-class, alongside magic links and email or SMS codes. Go fully passwordless or offer it as one option, with the same session and MFA primitives underneath either way.

Ship the login. Skip the liability.

Create a project, grab two keys, and authenticate your first user before this tab goes stale. No sales call required to start building.