n e w a u t h

You are the key

You are the key
SSO — sign-in for your team
Vault — deviceless credential storage
Extension — autofill logins
Mobile — coming soon
The Vault
Login button
wallet2o
mobile

Contact newauth

Flake based message

You can send a message through newauth's flake. Just click on the flake below.


Email

If you prefer email, you can send an email to

newauth@newauth.io

About newauth

What

Why

How

SSO

Pricing

FAQ


Every login method in use today — passwords, private keys, one-time codes, biometrics — relies on a secret that is created once and then kept around, waiting to be presented again.

That is the flaw. If a secret exists somewhere between logins, it can be found, copied, or stolen. Every password breach, every leaked database, every phished code comes down to this one fact.

newauth removes the secret entirely. Nothing is stored to steal, because nothing about your login exists until the moment you create it by clicking.



Personal account — requires a desktop or tablet (a wider screen makes clicking secret spots easier)

  • Create a newauth account
  • Set up newauth (choose your secret spots)
  • Sign in to newauth
  • Store a website credential in the newauth Vault
  • Use a website credential stored in the newauth Vault


SSO, reimagined. Give your organisation's apps a sign-in that works exactly like your personal newauth account — no passwords, no phone, no SMS. Users click secret spots on images. That is the whole login.

Standard, no lock-in

newauth speaks standard OpenID Connect. Any OIDC library or identity platform (Okta, Azure AD, Ping, Keycloak, Auth0, Spring Security, Auth.js…) works with it out of the box. Your directory, group policies, and access controls stay exactly where they are — newauth only replaces the login step.


Fits wherever you are today

Add it alongside your existing password login, wire it into your identity platform with one URL, replace sign-in entirely, or use it as a lightweight proof-of-presence check before sensitive actions. No existing infrastructure required to start.


Private by default

Every application your organisation registers gets a different, unlinkable identifier for the same user. Two of your own apps cannot tell they are looking at the same person unless you choose to link them.



Ready to add it to your site? See how SSO works or create a brand account to get your credentials.


Personal accounts

Free, forever. No card, no catch.


Brand / workforce accounts

Free up to 50 users on any application. Beyond that, plans scale per active user with rates that get cheaper as you grow — never a sudden jump.

Current plans and exact pricing are always up to date on the SSO pricing page, since rates can change and we would rather point you at the real number than a stale one written here.


Ready to see your plan? Create a brand account to get started — no payment required to try it.

What can I use newauth for?

  • Individuals

    • Organize and store passwords and other secrets in the newauth Vault.

    • Generate random, strong passwords for the sites that still need them.

    • Never type a website's ID and password again — copy and paste them.

    • Sign in with one click to any site or app that supports newauth.

  • Brands and organisations

    • Everything individuals get, plus:

    • Use newauth as your identity provider and stop fielding password-reset tickets.

    • Skip periodic forced password rotations for your users.

    • Simplify your login flow — newauth is naturally bot-resistant, so CAPTCHA becomes unnecessary.

    • Add your own login images so the experience feels like your brand, not a third party.

Is newauth a social network?

No, though it can feel a little like one. Your identifier changes every time you sign in, so you decide, per site, how much of yourself to show — from fully anonymous to fully named. Chatting and sharing with other newauth users is possible, but nothing about the product requires it.

Is newauth actually secure?

Nothing is stored that could be stolen, and the "password" is different every single time — both of those matter more than any one number. See the Why and What tabs for the entropy comparison against traditional passwords.

Want to see it in practice? Type tester1 in the username box and hit Enter — that account is a standing target and has weathered millions of real hack attempts. You are also welcome to try the #newauthchallenge yourself.

What can I store in the newauth Vault?

Any file. The Vault has two areas — website credentials (for your existing passwords) and general files.

Is my Vault data visible to newauth or its staff?

No. Vault data is encrypted with AES-256 on your own computer before it ever reaches our servers, and stays encrypted there. It is only decrypted back on your device, after you authenticate. Nobody at newauth can read it.

Can I access my Vault from any browser?

Yes, from any browser on any device. The fastest way is our "No Password" browser extension, currently available for Chrome and Firefox. Accessing the Vault through the website works everywhere too, just in a couple more clicks.

What is time fencing?

The ability to share a secret that cannot be opened until a specific time, even by the person holding it. Think of an exam paper that physically cannot be read before the start of the test — that same guarantee, applied to any secret you want to time-lock.

Can I add newauth sign-in to my website or app?

Yes. Create a brand account, register your application, and follow the step-by-step integration guide — it covers everything from a simple button add-on to replacing your login entirely.

newauth is a new way to sign in. No passwords, no one-time codes, no biometrics. newauth relies on your visual memory to identify you — you just click your secret locations on images. The name says it: authentication built on new information each time, never old information kept around. It starts easy, and gets harder automatically if someone tries to break in.


No passwords, private keys, biometrics or devices

newauth never uses information that exists before you sign in. Passwords, private keys, QR codes, and biometrics all exist beforehand — which is exactly what makes them stealable.

With newauth, clicking on images generates a brand-new password every single time. We call it a flake. Since every flake is unique, it doubles as your identifier too.


Simple

newauth is easier to use than a text password, not just more secure than one.

All you remember is where to click on a set of images. That is easier than typing a long, unnatural password — and it is the only kind of password you could produce while walking or running.


Secure

newauth authentication is orders of magnitude stronger than a traditional text password.

A strong 12-character password (e.g. EvR9L@i!#76y) -- mixing case, numbers and symbols — has an entropy of about 78 bits. A newauth flake from clicking on just 3 images already reaches roughly 91 bits.

Static passwords are only ever a matter of time before they fall. newauth's flake changes on every login, so there is nothing fixed sitting around to eventually be cracked.

Want to see it for yourself? Type tester1 in the username box and hit Enter — that account is a standing public target and has weathered millions of real hack attempts.


Adaptive

Sign-in gets harder on the fly, automatically, without you doing anything.

Each click places you at a point in multidimensional space, and the size of the image set determines how many dimensions that space has — which is what controls how hard the password is to guess. newauth controls that size directly.

Interestingly, this gives you the same protection as two-factor authentication, without the hassle of juggling a second device or typing a code from it.

A string of failed attempts should make the next attempt harder, not stay static. newauth does exactly that — difficulty rises automatically under repeated failure.


Click for more...


newauth also gives you proof of presence

Every newauth login produces a token called a flake. Because that flake did not exist a moment earlier and only one person could have created it, the flake itself is proof that a real person was there.

n e w a u t h . © 2 0 2 6 n e w a u t h

Loading...

... ... ... ... ... ...
  • Log in
  • Contact us
  • Create your newauth
  • Vault
  • Look up a flake