
Gluu Team
∙
Usernameless and Passwordless SSO for Gluu Server with WWPass


Gluu Team
∙
Usernameless and Passwordless SSO for Gluu Server with WWPass


Gluu Team
∙
Usernameless and Passwordless SSO for Gluu Server with WWPass

The Gluu Server and WWPass let users log in to their enabled applications with a WWPass Key (a mobile app, USB/NFC fob, or smart card) instead of a username and password. The integration provides multi-factor SSO over SAML or OAuth2, and the source code and installation instructions are available on GitHub.
What the Integration Provides
Capability | How it works with the Gluu Server |
|---|---|
Login credential | A WWPass Key ("something you have"), with a PIN or biometrics as the second factor |
SSO protocols | SAML or OAuth2 |
User identity | A PUID, a random number assigned to the user by the Gluu Server and stored in encrypted form in geographically distributed data centers |
Lost or damaged key | Self-revoke or replace the key with no impact on Gluu Server accounts and no re-enrollment |
Source code | Available on GitHub with installation instructions |
Good security starts at the login screen. With the WWPass mobile app or token, users can easily log in to all their enabled applications without the need for inherently insecure username/password architectures. For a broader look at the approach, see Passwordless SSO for Web & Mobile Apps and SSO Without Usernames.
Privacy by Design
WWPass technology keeps application data and user identity information separate and hidden from all other applications, preserving both user and application privacy, even from WWPass itself.
Unlike most common identity solutions, WWPass protects user identity with cryptography and zero-trust design. The WWPass Protected User Identifier (PUID) is a random number created by the Gluu Server, assigned to the user, and stored in the encrypted form in geographically distributed data centers. WWPass does not store or have access to any personal information. User identification and authorization remain under the enterprise's full control.
Logging In With a WWPass Key
To log in, users employ a WWPass Key. The WWPass Key is a cryptographic token available in the form of a mobile app, USB/NFC fob, or a smart card. With an addition of a PIN or biometrics, the WWPass Key serves as a strong two-factor authentication solution.
Unlike the others, WWPass uses "something you have" as the user's primary credential. This eliminates the need for username/password pairs and removes the login fields that first-order threats, from compromised credentials to SQL injection, rely on. Users enjoy the convenience of never having to remember username/password details again.
For how the WWPass Key compares with other hardware options, see FIDO2 Keys vs Smart Cards vs WWPass Key.
Lost or Damaged Keys Don't Mean Re-Enrollment
The WWPass Key's easy self-revoking or replacement procedure has no impact on user accounts in the Gluu Server, so there is no need to re-enroll the user if the key is lost or damaged.
SSO Over SAML or OAuth2
Gluu integration with WWPass hardware or software based cryptographic multi-factor authentication provides GDPR and NIST compliant strong SSO based on SAML or OAuth2 protocols for business applications, like Zoom and many others. For the source code and installation instructions, see the GitHub project and the Gluu Server site.
A Glimpse of the Future
WWPass provides a glimpse into a possible future for authentication: convenient, secure, flexible and strong, and without usernames!
FAQ
How does WWPass work with the Gluu Server?
Users authenticate with a WWPass Key, and the Gluu Server provides SSO to their enabled applications over SAML or OAuth2. The Gluu Server creates the PUID assigned to each user, which is stored in encrypted form in geographically distributed data centers.
What is a WWPass Key?
A cryptographic token available as a mobile app, a USB/NFC fob, or a smart card. With a PIN or biometrics added, it works as a strong two-factor authentication solution, with "something you have" as the primary credential.
What happens if a user loses their WWPass Key?
The user can revoke or replace it themselves. This has no impact on their accounts in the Gluu Server, so no re-enrollment is needed.
What is a PUID?
A Protected User Identifier: a random number assigned to the user and stored in encrypted form, which identifies them to a service without WWPass storing or accessing their personal information.
Where can I find the integration?
The source code and installation instructions are in the WWPass Gluu project on GitHub.
About WWPass
WWPass is a global cybersecurity company that provides next generation authentication and client-side encryption technology eliminating usernames and passwords. We battle data breaches and identity theft day in and day out, using our advanced distributed and secure storage mechanisms. Users get a secure experience, without compromising convenience.
The Gluu Server and WWPass let users log in to their enabled applications with a WWPass Key (a mobile app, USB/NFC fob, or smart card) instead of a username and password. The integration provides multi-factor SSO over SAML or OAuth2, and the source code and installation instructions are available on GitHub.
What the Integration Provides
Capability | How it works with the Gluu Server |
|---|---|
Login credential | A WWPass Key ("something you have"), with a PIN or biometrics as the second factor |
SSO protocols | SAML or OAuth2 |
User identity | A PUID, a random number assigned to the user by the Gluu Server and stored in encrypted form in geographically distributed data centers |
Lost or damaged key | Self-revoke or replace the key with no impact on Gluu Server accounts and no re-enrollment |
Source code | Available on GitHub with installation instructions |
Good security starts at the login screen. With the WWPass mobile app or token, users can easily log in to all their enabled applications without the need for inherently insecure username/password architectures. For a broader look at the approach, see Passwordless SSO for Web & Mobile Apps and SSO Without Usernames.
Privacy by Design
WWPass technology keeps application data and user identity information separate and hidden from all other applications, preserving both user and application privacy, even from WWPass itself.
Unlike most common identity solutions, WWPass protects user identity with cryptography and zero-trust design. The WWPass Protected User Identifier (PUID) is a random number created by the Gluu Server, assigned to the user, and stored in the encrypted form in geographically distributed data centers. WWPass does not store or have access to any personal information. User identification and authorization remain under the enterprise's full control.
Logging In With a WWPass Key
To log in, users employ a WWPass Key. The WWPass Key is a cryptographic token available in the form of a mobile app, USB/NFC fob, or a smart card. With an addition of a PIN or biometrics, the WWPass Key serves as a strong two-factor authentication solution.
Unlike the others, WWPass uses "something you have" as the user's primary credential. This eliminates the need for username/password pairs and removes the login fields that first-order threats, from compromised credentials to SQL injection, rely on. Users enjoy the convenience of never having to remember username/password details again.
For how the WWPass Key compares with other hardware options, see FIDO2 Keys vs Smart Cards vs WWPass Key.
Lost or Damaged Keys Don't Mean Re-Enrollment
The WWPass Key's easy self-revoking or replacement procedure has no impact on user accounts in the Gluu Server, so there is no need to re-enroll the user if the key is lost or damaged.
SSO Over SAML or OAuth2
Gluu integration with WWPass hardware or software based cryptographic multi-factor authentication provides GDPR and NIST compliant strong SSO based on SAML or OAuth2 protocols for business applications, like Zoom and many others. For the source code and installation instructions, see the GitHub project and the Gluu Server site.
A Glimpse of the Future
WWPass provides a glimpse into a possible future for authentication: convenient, secure, flexible and strong, and without usernames!
FAQ
How does WWPass work with the Gluu Server?
Users authenticate with a WWPass Key, and the Gluu Server provides SSO to their enabled applications over SAML or OAuth2. The Gluu Server creates the PUID assigned to each user, which is stored in encrypted form in geographically distributed data centers.
What is a WWPass Key?
A cryptographic token available as a mobile app, a USB/NFC fob, or a smart card. With a PIN or biometrics added, it works as a strong two-factor authentication solution, with "something you have" as the primary credential.
What happens if a user loses their WWPass Key?
The user can revoke or replace it themselves. This has no impact on their accounts in the Gluu Server, so no re-enrollment is needed.
What is a PUID?
A Protected User Identifier: a random number assigned to the user and stored in encrypted form, which identifies them to a service without WWPass storing or accessing their personal information.
Where can I find the integration?
The source code and installation instructions are in the WWPass Gluu project on GitHub.
About WWPass
WWPass is a global cybersecurity company that provides next generation authentication and client-side encryption technology eliminating usernames and passwords. We battle data breaches and identity theft day in and day out, using our advanced distributed and secure storage mechanisms. Users get a secure experience, without compromising convenience.
The Gluu Server and WWPass let users log in to their enabled applications with a WWPass Key (a mobile app, USB/NFC fob, or smart card) instead of a username and password. The integration provides multi-factor SSO over SAML or OAuth2, and the source code and installation instructions are available on GitHub.
What the Integration Provides
Capability | How it works with the Gluu Server |
|---|---|
Login credential | A WWPass Key ("something you have"), with a PIN or biometrics as the second factor |
SSO protocols | SAML or OAuth2 |
User identity | A PUID, a random number assigned to the user by the Gluu Server and stored in encrypted form in geographically distributed data centers |
Lost or damaged key | Self-revoke or replace the key with no impact on Gluu Server accounts and no re-enrollment |
Source code | Available on GitHub with installation instructions |
Good security starts at the login screen. With the WWPass mobile app or token, users can easily log in to all their enabled applications without the need for inherently insecure username/password architectures. For a broader look at the approach, see Passwordless SSO for Web & Mobile Apps and SSO Without Usernames.
Privacy by Design
WWPass technology keeps application data and user identity information separate and hidden from all other applications, preserving both user and application privacy, even from WWPass itself.
Unlike most common identity solutions, WWPass protects user identity with cryptography and zero-trust design. The WWPass Protected User Identifier (PUID) is a random number created by the Gluu Server, assigned to the user, and stored in the encrypted form in geographically distributed data centers. WWPass does not store or have access to any personal information. User identification and authorization remain under the enterprise's full control.
Logging In With a WWPass Key
To log in, users employ a WWPass Key. The WWPass Key is a cryptographic token available in the form of a mobile app, USB/NFC fob, or a smart card. With an addition of a PIN or biometrics, the WWPass Key serves as a strong two-factor authentication solution.
Unlike the others, WWPass uses "something you have" as the user's primary credential. This eliminates the need for username/password pairs and removes the login fields that first-order threats, from compromised credentials to SQL injection, rely on. Users enjoy the convenience of never having to remember username/password details again.
For how the WWPass Key compares with other hardware options, see FIDO2 Keys vs Smart Cards vs WWPass Key.
Lost or Damaged Keys Don't Mean Re-Enrollment
The WWPass Key's easy self-revoking or replacement procedure has no impact on user accounts in the Gluu Server, so there is no need to re-enroll the user if the key is lost or damaged.
SSO Over SAML or OAuth2
Gluu integration with WWPass hardware or software based cryptographic multi-factor authentication provides GDPR and NIST compliant strong SSO based on SAML or OAuth2 protocols for business applications, like Zoom and many others. For the source code and installation instructions, see the GitHub project and the Gluu Server site.
A Glimpse of the Future
WWPass provides a glimpse into a possible future for authentication: convenient, secure, flexible and strong, and without usernames!
FAQ
How does WWPass work with the Gluu Server?
Users authenticate with a WWPass Key, and the Gluu Server provides SSO to their enabled applications over SAML or OAuth2. The Gluu Server creates the PUID assigned to each user, which is stored in encrypted form in geographically distributed data centers.
What is a WWPass Key?
A cryptographic token available as a mobile app, a USB/NFC fob, or a smart card. With a PIN or biometrics added, it works as a strong two-factor authentication solution, with "something you have" as the primary credential.
What happens if a user loses their WWPass Key?
The user can revoke or replace it themselves. This has no impact on their accounts in the Gluu Server, so no re-enrollment is needed.
What is a PUID?
A Protected User Identifier: a random number assigned to the user and stored in encrypted form, which identifies them to a service without WWPass storing or accessing their personal information.
Where can I find the integration?
The source code and installation instructions are in the WWPass Gluu project on GitHub.
About WWPass
WWPass is a global cybersecurity company that provides next generation authentication and client-side encryption technology eliminating usernames and passwords. We battle data breaches and identity theft day in and day out, using our advanced distributed and secure storage mechanisms. Users get a secure experience, without compromising convenience.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.
