Technology

MFA ∙ Multifactor authentication without a username or password

Most MFA solutions add a second factor on top of a username and password. WWPass replaces both. There is no username in the system. There is no password to steal, reuse, or phish. The WWPass Key is the only credential.

Technology

MFA ∙ Multifactor authentication without a username or password

Most MFA solutions add a second factor on top of a username and password. WWPass replaces both. There is no username in the system. There is no password to steal, reuse, or phish. The WWPass Key is the only credential.

Technology

MFA ∙ Multifactor authentication without a username or password

Most MFA solutions add a second factor on top of a username and password. WWPass replaces both. There is no username in the system. There is no password to steal, reuse, or phish. The WWPass Key is the only credential.

Why traditional MFA is not enough

Traditional MFA works by adding a second verification step to a first factor that is still a username and password. The username is still exposed. The password is still stored somewhere. If either is stolen, the second factor becomes the only thing standing between an attacker and access.

SMS-based two-factor authentication was deprecated by NIST in 2016. OTP-based authentication requires a dedicated server with high availability and a geographically distributed backup. 

Smartcard-based systems are not flexible, poorly scalable, and expensive. Each approach adds friction without removing the underlying credential risk.


What WWPass MFA actually does

WWPass uses something the user has — a WWPass Key token or mobile app — as the primary credential. This replaces the username and password entirely. There is no first factor to compromise before the second factor can protect it.

Each login uses a dynamic QR code containing only a one-time session ticket. The ticket is valid for a single session. It cannot be reused. It cannot be phished. The service never receives a username or a human-readable credential of any kind.

Explore how WWPass works


One key, every application

A single WWPass Key authenticates across every WWPass-enabled service. Users never need to remember or manage credentials for individual applications. Access from computers, phones, and tablets is supported through the same key.

Each service receives a unique opaque identifier specific to that user and that service. Data about one application is kept separate from every other, preserving both user and application privacy.

Explore PUID ∙ Protected user identifier


Authentication factors

The WWPass Key serves as the primary factor: something the user has. An optional PIN or biometric can be added as a second factor at the service provider's discretion. Additional controls including IP whitelists and geolocation can be applied where required.

With a hardware WWPass Key and PIN or biometric, authentication reaches Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B, the highest level defined.


Self-service key management

Users manage their own keys without IT involvement. A hardware key can be revoked and reissued by the user if it is lost or stolen. A separate Service Key, issued alongside the primary key, handles all key management operations. Self-service management reduces service desk costs and removes the password reset workflow.

Explore WWPass Key


Where it fits in the stack

WWPass MFA integrates with existing applications and infrastructure through SAML, OAuth2, and OIDC. It works for finance and healthcare settings where regulatory requirements are highest, and scales for consumer-facing applications. Both hardware tokens and mobile app are supported across any device and browser.

Self-service management reduces credential-related support tickets significantly. Simplifies compliance posture by removing the attack surface that traditional MFA only partially covers.


Frequently asked questions

Q: Is WWPass MFA a second factor added to a username and password?

A: No. WWPass replaces the username and password entirely. The WWPass Key is the primary credential. An optional PIN or biometric can be added as a second factor, but there is no underlying username or password for an attacker to steal first.

Q: Why is SMS two-factor authentication not recommended?

A: NIST deprecated SMS-based two-factor authentication in 2016. Its Digital Identity Guidelines note that out-of-band verification using SMS is deprecated and will no longer be permitted in future releases of that guidance.

Q: What devices does WWPass MFA support?

A: WWPass MFA works on any device and browser. The WWPass Key is available as a hardware token (smartcard, USB key, NFC token) or as a mobile app for iOS and Android.

Q: What assurance level does WWPass MFA reach?

A: With a hardware WWPass Key and PIN or biometric, authentication reaches AAL3 as defined in NIST SP 800-63B, the highest level defined.

Q: What happens if a user loses their WWPass Key?

A: The user uses their Service Key to revoke the lost key and issue a new one. No administrator involvement is required. WWPass itself cannot recover access; the user retains full control through the Service Key.

Why traditional MFA is not enough

Traditional MFA works by adding a second verification step to a first factor that is still a username and password. The username is still exposed. The password is still stored somewhere. If either is stolen, the second factor becomes the only thing standing between an attacker and access.

SMS-based two-factor authentication was deprecated by NIST in 2016. OTP-based authentication requires a dedicated server with high availability and a geographically distributed backup. 

Smartcard-based systems are not flexible, poorly scalable, and expensive. Each approach adds friction without removing the underlying credential risk.


What WWPass MFA actually does

WWPass uses something the user has — a WWPass Key token or mobile app — as the primary credential. This replaces the username and password entirely. There is no first factor to compromise before the second factor can protect it.

Each login uses a dynamic QR code containing only a one-time session ticket. The ticket is valid for a single session. It cannot be reused. It cannot be phished. The service never receives a username or a human-readable credential of any kind.

Explore how WWPass works


One key, every application

A single WWPass Key authenticates across every WWPass-enabled service. Users never need to remember or manage credentials for individual applications. Access from computers, phones, and tablets is supported through the same key.

Each service receives a unique opaque identifier specific to that user and that service. Data about one application is kept separate from every other, preserving both user and application privacy.

Explore PUID ∙ Protected user identifier


Authentication factors

The WWPass Key serves as the primary factor: something the user has. An optional PIN or biometric can be added as a second factor at the service provider's discretion. Additional controls including IP whitelists and geolocation can be applied where required.

With a hardware WWPass Key and PIN or biometric, authentication reaches Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B, the highest level defined.


Self-service key management

Users manage their own keys without IT involvement. A hardware key can be revoked and reissued by the user if it is lost or stolen. A separate Service Key, issued alongside the primary key, handles all key management operations. Self-service management reduces service desk costs and removes the password reset workflow.

Explore WWPass Key


Where it fits in the stack

WWPass MFA integrates with existing applications and infrastructure through SAML, OAuth2, and OIDC. It works for finance and healthcare settings where regulatory requirements are highest, and scales for consumer-facing applications. Both hardware tokens and mobile app are supported across any device and browser.

Self-service management reduces credential-related support tickets significantly. Simplifies compliance posture by removing the attack surface that traditional MFA only partially covers.


Frequently asked questions

Q: Is WWPass MFA a second factor added to a username and password?

A: No. WWPass replaces the username and password entirely. The WWPass Key is the primary credential. An optional PIN or biometric can be added as a second factor, but there is no underlying username or password for an attacker to steal first.

Q: Why is SMS two-factor authentication not recommended?

A: NIST deprecated SMS-based two-factor authentication in 2016. Its Digital Identity Guidelines note that out-of-band verification using SMS is deprecated and will no longer be permitted in future releases of that guidance.

Q: What devices does WWPass MFA support?

A: WWPass MFA works on any device and browser. The WWPass Key is available as a hardware token (smartcard, USB key, NFC token) or as a mobile app for iOS and Android.

Q: What assurance level does WWPass MFA reach?

A: With a hardware WWPass Key and PIN or biometric, authentication reaches AAL3 as defined in NIST SP 800-63B, the highest level defined.

Q: What happens if a user loses their WWPass Key?

A: The user uses their Service Key to revoke the lost key and issue a new one. No administrator involvement is required. WWPass itself cannot recover access; the user retains full control through the Service Key.

Why traditional MFA is not enough

Traditional MFA works by adding a second verification step to a first factor that is still a username and password. The username is still exposed. The password is still stored somewhere. If either is stolen, the second factor becomes the only thing standing between an attacker and access.

SMS-based two-factor authentication was deprecated by NIST in 2016. OTP-based authentication requires a dedicated server with high availability and a geographically distributed backup. 

Smartcard-based systems are not flexible, poorly scalable, and expensive. Each approach adds friction without removing the underlying credential risk.


What WWPass MFA actually does

WWPass uses something the user has — a WWPass Key token or mobile app — as the primary credential. This replaces the username and password entirely. There is no first factor to compromise before the second factor can protect it.

Each login uses a dynamic QR code containing only a one-time session ticket. The ticket is valid for a single session. It cannot be reused. It cannot be phished. The service never receives a username or a human-readable credential of any kind.

Explore how WWPass works


One key, every application

A single WWPass Key authenticates across every WWPass-enabled service. Users never need to remember or manage credentials for individual applications. Access from computers, phones, and tablets is supported through the same key.

Each service receives a unique opaque identifier specific to that user and that service. Data about one application is kept separate from every other, preserving both user and application privacy.

Explore PUID ∙ Protected user identifier


Authentication factors

The WWPass Key serves as the primary factor: something the user has. An optional PIN or biometric can be added as a second factor at the service provider's discretion. Additional controls including IP whitelists and geolocation can be applied where required.

With a hardware WWPass Key and PIN or biometric, authentication reaches Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B, the highest level defined.


Self-service key management

Users manage their own keys without IT involvement. A hardware key can be revoked and reissued by the user if it is lost or stolen. A separate Service Key, issued alongside the primary key, handles all key management operations. Self-service management reduces service desk costs and removes the password reset workflow.

Explore WWPass Key


Where it fits in the stack

WWPass MFA integrates with existing applications and infrastructure through SAML, OAuth2, and OIDC. It works for finance and healthcare settings where regulatory requirements are highest, and scales for consumer-facing applications. Both hardware tokens and mobile app are supported across any device and browser.

Self-service management reduces credential-related support tickets significantly. Simplifies compliance posture by removing the attack surface that traditional MFA only partially covers.


Frequently asked questions

Q: Is WWPass MFA a second factor added to a username and password?

A: No. WWPass replaces the username and password entirely. The WWPass Key is the primary credential. An optional PIN or biometric can be added as a second factor, but there is no underlying username or password for an attacker to steal first.

Q: Why is SMS two-factor authentication not recommended?

A: NIST deprecated SMS-based two-factor authentication in 2016. Its Digital Identity Guidelines note that out-of-band verification using SMS is deprecated and will no longer be permitted in future releases of that guidance.

Q: What devices does WWPass MFA support?

A: WWPass MFA works on any device and browser. The WWPass Key is available as a hardware token (smartcard, USB key, NFC token) or as a mobile app for iOS and Android.

Q: What assurance level does WWPass MFA reach?

A: With a hardware WWPass Key and PIN or biometric, authentication reaches AAL3 as defined in NIST SP 800-63B, the highest level defined.

Q: What happens if a user loses their WWPass Key?

A: The user uses their Service Key to revoke the lost key and issue a new one. No administrator involvement is required. WWPass itself cannot recover access; the user retains full control through the Service Key.

Get WWPass

Download the WWPass Key app and test authentication without a username or password.

© 2026 World Wide Pass — WWPass

Get WWPass

Download the WWPass Key app and test authentication without a username or password.

© 2026 World Wide Pass — WWPass

Get WWPass

Download the WWPass Key app and test authentication without a username or password.

© 2026 World Wide Pass — WWPass