Stytch Passwords is a re-imagination of the legacy auth method, retrofitted with nimbler breach detection, smarter strength assessments, safe account deduplication and a simpler password reset flow.
Hi Product Hunt 👋,
We’re the founders of Stytch, a modern identity and access management platform. My co-founder, Reed, and I met at Plaid back in 2017 -- during our time there, we both worked on the user authentication features that millions of people use to connect their bank accounts to apps like Venmo, Coinbase, and Robinhood. While working on these projects, we experienced first-hand how frustrating it is to build authentication flows. In addition to being complicated, resource-intensive, and error-prone to build in-house, we saw a fundamental issue with the fact that the oldest and most common form of authentication (Passwords) poses significant security and user experience risks.
We founded Stytch to elevate both the developer and end-user experience of customer authentication. Historically, it’s been too difficult to build exceptional authentication experiences – and given how critical sign-up and login is to companies (it’s a customer’s first touchpoint, a major conversion lever, and the way you protect customers’ sensitive data), we wanted to reimagine what the developer and customer experience could look like when it comes to authentication.
When founding Stytch in 2020, we started by building out a suite of passwordless authentication options (biometrics, magic links, passcodes, social logins, etc.), and today, we’re excited to introduce a modern upgrade to the oldest form of online authentication: passwords. With our new passwords product, we’ve innovated from the ground up to uplevel security and user experience.
Here’s what Stytch’s solution has to offer:
👀 Breach detection: password reuse opens the possibility of credential stuffing attacks. Stytch integrates with HaveIBeenPwnd and prevents users from setting passwords that are present in their dataset of nearly 12 billion compromised credentials. Every time someone logs in with a password, Stytch checks HaveIBeenPwnd to see if those credentials have been compromised since last authentication and triggers a password reset if a breach is detected.
💪 Strength assessment: in the face of password overload, users default to using easy-to-guess passwords. Stytch uses Dropbox’s zxcvbn password strength estimator, which provides a flexible strength assessment based on how resistant a password is to modern password guessing techniques. This feature is designed to make picking a strong password easy for humans to generate and hard for robots to guess.
👯♀️ Safe account de-duplication: Stytch de-duplicates accounts by email regardless of the authentication method. This allows users to change which authentication option they are using to log in to an app without accidentally creating a new account (e.g. a password user can switch to sign in via Google OAuth) or being forced to re-authenticate with the same method originally used.
👪 More human-centric password reset: when an end user triggers a password reset, most of the time they really just want to access their account, not change their password. With Stytch, customers have the option to integrate a traditional password-reset email OR integrate a password reset powered by Email Magic Links for a more seamless experience. We’re building our password-reset email template to be more human-centric, focusing more on UX and conversions than traditional password-reset flows.
In addition to these upgrades to password-based authentication, Stytch is a full identity and access management platform. Alongside our passwords product, you can integrate authorization, multi-factor authentication, passwordless auth, and more!
If you want to learn more about our Passwords product, check out our documentation here: https://stytch.com/docs/passwords
Reed, myself and the rest of the team would love to hear your feedback!
@jelamb Congratulations on the launch! Tell me, do you have a ready-made secure solution for browser extensions? I know it's a small market, but right now, it's empty.
Report
@jelamb Congrats! Discovered through Invincible Product Hunters community :)
@yankovichv thank you! we don't have any guides on how to do this but it is easy to do with either our js sdk or direct api, if you want to email support@stytch.com, someone can help you get integrated!
Report
As a great philosopher once said - "Identity theft is not a joke, millions of families suffer every year!" - This is a great product to help people beef up their online security.
Congratulations on the launch! :)
Report
@shrikant_damani thanks! We’re trying to make protecting user and accounts effortless for both developers and users — great to hear that resonates!
Report
Congrats on your launch! Nice design, looks super clean and user-friendly.
Replies
Stytch
Manganum sidebar for Google Chrome
Stytch
Stytch
Scalenut
Scalenut
Outerbridge
NVSTly: Social Investing
Adsby
Stytch