Prompt
passwordless auth api
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
If you want a passwordless authentication API, the common options are:
1) Magic link
- User enters email
- API sends a one-time sign-in link
- Clicking the link authenticates the user
2) OTP / verification code
- User enters email or phone
- API sends a 6-digit code
- User submits the code to log in
3) Passkeys
- User signs in with device biometrics / platform authenticator
- More secure and modern, but more complex to implement
Typical API flow
Request sign-in
POST /auth/passwordless/request
{
"email": "user@example.com"
}
Response:
{
"message": "If the account exists, a sign-in link/code has been sent."
}
Verify code or token
POST /auth/passwordless/verify
{
"email": "user@example.com",
"code": "123456"
}
Response:
{
"access_token": "jwt_here",
"refresh_token": "refresh_here",
"user": {
"id": "123",
"email": "user@example.com"
}
}
Security notes
- Use short expiration: 5–15 minutes
- Make tokens single-use
- Store only hashed verification tokens
- Add rate limiting and abuse protection
- Return generic responses to prevent account enumeration
- Prefer email verification links or TOTP/OTP over insecure custom flows
- For production, use JWT access tokens + refresh tokens or secure session cookies
Example stack choices
- Auth.js / NextAuth for web apps
- Clerk, Supabase Auth, Firebase Auth, Auth0 for managed solutions
- Custom backend: Node.js + Redis + email provider (SendGrid/Mailgun/Postmark)
If you want, I can generate:
- a Node/Express passwordless auth API,
- a FastAPI implementation, or
- a database schema + endpoint design.