Who is participating?
Authenticate the enrolled account with the configured factors.
How it works / Full Duplex Authentication®
An organization needs to authenticate its user. The person also needs a reason to trust the service asking for approval. Full Duplex Authentication makes that relationship work in both directions.
501
501Full Duplex Authentication connects account authentication, the enrolled app’s server relationship and a deliberate human decision. The comparison is the visible part of that experience.
Starts the request and owns account access or the pending operation.
Handles the configured authentication exchange.
Verifies its established authentication-server relationship.
Checks the request they initiated or expected, then chooses.
Authenticate the enrolled account with the configured factors.
The enrolled app checks its authentication server; the integration connects that server to the application.
A request can be expected without being initiated by the person, such as an agent-prepared action. The person still decides.
The customer sign-in example uses the documented BigCommerce LoginFree™ flow: scan the store’s QR code, compare the black picture and number on browser and phone, and accept in the browser. The customer reaches their account and the phone confirms success.
PasswordFree® · BigCommerce LoginFree · interactive example
An enrolled customer chooses PasswordFree to return to their account. Try the sign-in button in the store.
Your orders. Your account.
Open the enrolled app and point the phone at the store’s QR code. Here, select Scan QR code in the phone’s viewfinder.

Point your camera at the store

Compare the black picture and code on the two screens. If they match, select Accept in the store. If anything looks wrong, select Decline.
Do the picture and number match your phone?
501Compare with the store
501If they match, select Accept in the store. Otherwise, select Decline.
The store opens the customer account and the phone shows a green confirmation.
Try the highlighted button or use the controls below.
A person may be signed in while a particular operation still needs their approval. NoPass can request a fresh confirmation on the phone at that point. The application holds the operation and uses the response in its execution policy.
Authentication establishes the account relationship. Application permissions decide what that account may do; an operation-approval step asks for the person’s decision when it matters.
FDA authenticates an enrolled account in a configured service relationship. Initial identity proofing or KYC belongs to the organization’s separate process.
No. The enrolled app’s authentication-server relationship and the integration are distinct from the comparison presented to the person.
WebAuthn/FIDO2 supports phishing-resistant authentication through verifier-name binding. Start with an access or approval workflow you need to improve, and compare integration, user experience and recovery. FDA is not a replacement for every existing identity or authorization control.
Full Duplex Authentication is the shared foundation. Choose around the people and systems you serve.

Passwordless registration and sign-in for customer accounts, with integrations for supported stores and applications.
Explore customer access
Passwordless workforce access and approval checkpoints for sensitive actions in your applications.
Explore NoPassRead the patent, examine the published architecture and follow an implemented customer journey. A patent describes an invention; it is not a certification of a deployment.
A matching picture is not a reason to approve an unexpected action. Keep the account closed, decline the request and use the service’s known support route.
The service is waiting for the person’s decision.
Check the picture and number against the service you are using. A match alone does not grant permission.
This example shows a person choosing to decline; it does not simulate automatic attack detection.