Prompt
I’m building a regulated app and need stronger identity verification, what authentication approach should I use?
Latest observation
For a regulated app, the safest default is to use modern, standards-based authentication with phishing-resistant MFA, and for higher assurance step up to passkeys and/or hardware-backed factors. In practice:
Recommended approach
-
Use an external identity provider (IdP) that supports:
- OpenID Connect (OIDC) / OAuth 2.0
- Multi-factor authentication (MFA)
- Passkeys (WebAuthn/FIDO2)
- Risk-based or step-up authentication
- Audit logs, user lifecycle, and compliance features
-
Prefer phishing-resistant authentication
- Passkeys (WebAuthn/FIDO2) are the best general-purpose option today.
- For very high assurance, require hardware security keys or passkeys with device binding where supported.
- Avoid relying only on SMS or email OTP for regulated/high-risk use cases.
-
Use step-up authentication for sensitive actions
- Keep normal login smooth.
- Require stronger verification for actions like:
- changing account details
- viewing protected data
- approving transfers/signatures
- changing MFA settings
-
Follow a strong session model
- Short-lived access tokens
- Secure refresh token handling
- Re-authentication after sensitive events
- Device/session revocation support
What to avoid
- Password-only authentication
- SMS OTP as the primary or only MFA
- Building your own auth system unless absolutely necessary
- Storing secrets or tokens insecurely on the client
Best practical choice
If you want a clear recommendation:
Use OIDC with an enterprise-grade IdP, require passkeys or hardware-backed MFA, and enforce step-up authentication for sensitive workflows.
If you need to meet stricter regulatory requirements
Depending on your domain, you may also need:
- Identity proofing / KYC
- Document + selfie verification
- TOTP or FIDO2 enrollment policies
- Centralized audit trails
- Least-privilege authorization layered on top of auth
If you tell me what regulation or industry you’re in (e.g. healthcare, fintech, government, SOC 2, HIPAA, PCI, GDPR, PSD2), I can recommend a more precise auth pattern.