Prompt
I'm building a B2B app that already uses SSO. How can I add passwordless access?
Latest observation
You can add passwordless access to an existing SSO-based B2B app in a few ways, and the best choice depends on whether you want to keep the SSO provider as the primary identity layer or let users sign in directly to your app.
Common approaches
1) Add passwordless as an identity method in your IdP/SSO provider
If your app already relies on an IdP like Okta, Azure AD, Ping, Auth0, etc., the cleanest approach is often to enable passwordless there:
- Email magic links
- OTP codes via email or SMS
- Passkeys/WebAuthn
- IdP-native passwordless policies
Why this is good:
- Keeps one login flow
- Centralizes policy, MFA, session handling, and auditing
- Works well for enterprises already using SSO
Watch out for:
- Some enterprise IdPs restrict consumer-style passwordless options
- SMS is usually weaker and often discouraged for B2B admin access
- Magic links can be awkward if users work behind link-scanning security tools
2) Support passwordless for non-SSO users, keep SSO for enterprise users
This is a common hybrid model:
- Enterprise customers can continue using SAML/OIDC SSO
- Smaller customers, contractors, or internal admins can use passwordless login directly
Typical passwordless methods:
- Passkeys (recommended): best security and UX
- Email magic link: easiest to implement
- Email one-time code: simple fallback
Why this works well:
- You don’t break existing SSO customers
- You broaden access options for users without corporate IdPs
- You can gradually migrate users to passwordless
3) Use passwordless as a step-up or fallback to SSO
In some apps, passwordless is not the primary login, but:
- Used to verify a user when SSO is unavailable
- Used for account recovery
- Used to confirm sensitive actions
- Used for specific user segments, like admins or external collaborators
This is useful if you want to keep strict enterprise SSO while improving resilience.
Best passwordless method for B2B
Passkeys are usually the best long-term option
Passkeys use WebAuthn/FIDO2 and let users authenticate with:
- Device biometrics
- Device PIN
- Hardware security keys
Pros:
- Phishing-resistant
- Better security than email/SMS OTP
- Strong user experience on modern platforms
- Good fit for enterprise security requirements
Cons:
- More implementation complexity than email links
- Some users may need onboarding/help on older devices or browsers
If your audience includes security-conscious enterprises, passkeys are increasingly the strongest choice.
Email magic links are the easiest to launch
Pros:
- Very easy for users
- Minimal friction
- Good for initial rollout
Cons:
- Link-scanning and email forwarding can create reliability/security issues
- Depends on email deliverability
- Less strong than passkeys for high-security environments
A lot of B2B products start here, then add passkeys later.
OTP via email is a decent fallback
Pros:
- Simpler than magic links in some environments
- Easier to handle in clients where links are problematic
Cons:
- Still depends on email
- Slightly more friction than magic links
- Not as strong as passkeys
Recommended architecture
If you already have SSO via OIDC/SAML
A common pattern is:
- User enters email
- Your app determines whether the domain is SSO-managed
- If yes:
- Route to SSO login
- If no:
- Offer passwordless login options
- After authentication, create the same app session regardless of method
This lets you support both:
- Enterprise SSO
- Passwordless direct login
You can also allow a single account to have both SSO and passwordless methods linked, if your product model supports it.
Important design considerations
1) Account linking
If a user can authenticate via both SSO and passwordless, decide how identities connect:
- By verified email
- By enterprise domain
- By explicit admin invitation
- By account linking flow
Be careful to avoid accidental account takeover through email-only matching.
2) Domain-based routing
For B2B, it’s common to detect the user’s email domain and:
- Send managed domains to SSO
- Allow passwordless for unmanaged domains or guest users
This improves UX, but don’t rely on domain alone for security decisions.
3) Security and policy
For enterprise use, consider:
- Passkeys for primary auth
- Email magic links only for lower-risk cases
- MFA/step-up for sensitive actions
- Session timeout and device trust policies
- Admin controls to require SSO, passwordless, or both
4) User lifecycle
Think through:
- New user onboarding
- Invite flows
- Account recovery
- Changing email addresses
- Revoking a passkey or magic-link access
- Deprovisioning users when they leave a customer org
A practical rollout plan
Phase 1: Add email magic link or email code
- Fastest path to passwordless
- Good for proving the flow
- Keep SSO untouched
Phase 2: Add passkeys
- Offer as the preferred method
- Support platform authenticators and security keys
- Make it available for admins and frequent users first
Phase 3: Add policy controls
- Org-level auth settings
- Require SSO for some customers
- Allow passwordless for others
- Step-up auth for sensitive operations
What I’d recommend
For a B2B app that already has SSO:
- Keep SSO as-is
- Add passkeys as the primary passwordless option
- Use email magic link or OTP as a simpler fallback
- Support org-level auth policy
- Design account linking carefully
If you want, I can also help you with:
- A recommended login flow diagram
- A comparison of magic links vs passkeys vs OTP
- An implementation approach for OIDC/SAML-based apps
- UX copy for a B2B passwordless sign-in screen