Skip to content
IdentitéTrust starts here
English
EnglishEspañolPortuguês
Contact

How it works / Full Duplex Authentication®

How does your user know it is really you?

An organization needs to authenticate its user. The person also needs a reason to trust the service asking for approval. Full Duplex Authentication makes that relationship work in both directions.

Your service
Black comparison figure501
Your enrolled app
Black comparison figure501
A relationship both sides can check.

Explore the trust architecture.

Verifiable identity is the cornerstone of digital trust.

Full Duplex Authentication connects account authentication, the enrolled app’s server relationship and a deliberate human decision. The comparison is the visible part of that experience.

  1. Requesting application

    Starts the request and owns account access or the pending operation.

  2. NoPass™ authentication server

    Handles the configured authentication exchange.

  3. Enrolled app

    Verifies its established authentication-server relationship.

  4. The person

    Checks the request they initiated or expected, then chooses.

Identity

Who is participating?

Authenticate the enrolled account with the configured factors.

Destination

Is this the connected service?

The enrolled app checks its authentication server; the integration connects that server to the application.

Intent

Is this the request I meant to approve?

A request can be expected without being initiated by the person, such as an agent-prepared action. The person still decides.

See what the person actually does.

The customer sign-in example uses the documented BigCommerce LoginFree™ flow: scan the store’s QR code, compare the black picture and number on browser and phone, and accept in the browser. The customer reaches their account and the phone confirms success.

PasswordFree® · BigCommerce LoginFree · interactive example

Start at the store.

An enrolled customer chooses PasswordFree to return to their account. Try the sign-in button in the store.

Your store
Your store

Welcome back.

Your orders. Your account.

PasswordFree
Enrolled appA familiar
way back.

Try the highlighted button or use the controls below.

Trust also matters after sign-in.

A person may be signed in while a particular operation still needs their approval. NoPass can request a fresh confirmation on the phone at that point. The application holds the operation and uses the response in its execution policy.

Authentication establishes the account relationship. Application permissions decide what that account may do; an operation-approval step asks for the person’s decision when it matters.

An enrolled account is not identity proofing.

Does FDA establish a person’s legal identity?

FDA authenticates an enrolled account in a configured service relationship. Initial identity proofing or KYC belongs to the organization’s separate process.

Does the picture replace the server checks?

No. The enrolled app’s authentication-server relationship and the integration are distinct from the comparison presented to the person.

We already use passkeys or MFA. What should we evaluate?

WebAuthn/FIDO2 supports phishing-resistant authentication through verifier-name binding. Start with an access or approval workflow you need to improve, and compare integration, user experience and recovery. FDA is not a replacement for every existing identity or authorization control.

One foundation for two product families.

One trust architecture. Two authentication experiences.

Full Duplex Authentication is the shared foundation. Choose around the people and systems you serve.

PasswordFree®

Passwordless registration and sign-in for customer accounts, with integrations for supported stores and applications.

Explore customer access

NoPass™

Passwordless workforce access and approval checkpoints for sensitive actions in your applications.

Explore NoPass
Full Duplex Authentication — the shared foundation

Inspect the implementation.

Examine the mechanism and the experience.

Read the patent, examine the published architecture and follow an implemented customer journey. A patent describes an invention; it is not a certification of a deployment.

What if you did not start this request?

A matching picture is not a reason to approve an unexpected action. Keep the account closed, decline the request and use the service’s known support route.

Which request are you reviewing?

Connected service

The service is waiting for the person’s decision.

Your enrolled app

Check the picture and number against the service you are using. A match alone does not grant permission.

This example shows a person choosing to decline; it does not simulate automatic attack detection.