How it works

How AuthLN ends attacks before login completes

Legitimate users sign in passwordless in about a second and never feel a thing. Everyone else hits a real cost before authentication completes, and most abandon rather than pay it. Here's exactly how.

What it does

One gate. Three outcomes. No risk scores.

AuthLN adds a single factor to every login: an economic gate in front of your existing identity provider. Real users clear it instantly with a passkey. Everyone else has to settle it first. The result is less noise, cleaner signal, and a record of every attempt - including the ones that walk away.

Legitimate users never feel it

A passkey clears the gate in about 1.2 seconds. No payment, no extra step, nothing to learn.

Attackers meet a cost

The only way past is to settle a Lightning invoice. Most abandon at the price; whoever pays is still denied.

Every attempt is evidence

Who tried, when, from where, and how it ended - logged per user, ready for your team.

The flow

Five steps - under a second for real users

Every attemptmust satisfy the gate

PFA gate
One passkey scanno cost, no friction
Your identity providerOkta · Entra ID · Google Workspace · JumpCloud · and more
Pay per attempta real, configurable cost
Still verified, still deniedor they walk away - recorded either way

AuthLN sits in front of the identity provider you already run. Every attempt goes through the same gate; the five steps below are that path in detail.

01

Login starts

A user signs in through the identity provider you already run - Okta, Microsoft Entra ID, or Google.

02

The gate appears

AuthLN places a Lightning invoice in front of the attempt. Real users never see it.

03

Passkey confirms

A device-bound Post-Quantum Encryption (PQE) passkey in the Secure Enclave proves it's really them - no password to phish.

04

Invoice clears

Authorized users cancel it instantly and pay nothing. Everyone else has to fund it from their own wallet.

05

In, or on record

Real users are in. Unauthorized attempts are stopped, logged, and traced back to their source.

Two paths

The same gate, opposite experiences

Authorized users

In about 1.2 seconds - and they never pay.

  • Present a device-bound passkey from the hardware enclave.
  • The invoice clears automatically - no payment, nothing to see.
  • No passwords, so nothing to phish or replay.

Everyone else

Pay real money to even try - most abandon instead.

  • With no passkey, the only way forward is to fund the invoice.
  • Automating payment automates their own bill, and every settled invoice leaves a trail.
  • Whoever does pay is still denied on identity - and traced.
Then your policy takes over. Every unauthorized attempt is captured - payment, origin, credential, and timing - and your security policy decides the response: alert your SOC, isolate the pattern, or escalate to incident response.

We don't block attacks - we price them.

Authorized users log in normally. Every unauthorized attempt carries a cost and becomes a record. See it running in front of your own identity provider.

Schedule a Demo