Passwords get guessed, reused, phished and leaked. Auth22 replaces them with something only you can produce, on a device only you hold.
Free while in preview · Android app required to finish setup
Sign in with Google and pick your username. Takes about a minute.
The app sets up your phone as your key and walks you through the rest.
On a site that supports Auth22, confirm on your phone. Nothing to type, nothing to remember.
The point isn't a better password. It's that there is nothing worth stealing in the first place.
No password is stored on our servers or a site's, because there is no password. A breach has nothing to spill.
There is no secret you could be tricked into typing into the wrong box, because you never type one.
Approval happens on your own phone, and stays there. Someone with your details, on their device, gets nowhere.
Every request shows what it's for and how long it's valid. If it wasn't you, ignore it and it dies.