32 karma · joined January 20, 2022
felix@hanko.io
To be upfront about this, we’re still on AWS (Frankfurt), but "EU-owned" hosting/data regions will be available very soon.
Granted, Hanko Cloud is still running on AWS (Frankfurt), but we’re working on alternative EU data location options right now.
The js SDK is almost done, mostly the docs are still missing, so I'd say 2-3 weeks. For mobile SDKs we're currently evaluating Kotlin Multiplatform, ideally that can help us manage the overhead a bit. We'd love to release them in March, but can't make promises yet. That said, the Flow API (which handles all states for you) can be used perfectly without an SDK and we have multiple customers that have done that for their production apps.
As long as you are satisfied with passkeys being "usernameless" (i.e. discoverable), you can offer a nice login flow with a "Sign in with a passkey" button and Passkey Autofill.
For 2FA use cases, you should provide a second WebAuthn configuration that does not require discoverable credentials, for example, and does not necessarily require user verification.
This allows a user to have both fully-fledged passkeys and, for example, security keys as a second factor to secure username/password-based login. Users can choose what they want to do (create a passkey on e.g. iCloud or add security keys as 2FA without using precious key storage resources on the hardware tokens).
GitHub has done a very solid implementation of that model, and we are working on adopting it to our services and it's looking very good so far.
With that being said, we are not happy with how password managers have implemented passkey intercepts, but ultimately that's a decision the user can make, as it can be disabled in the browser extension settings.
I look forward to putting out many more bounties on Algora.
Edit: here's the link to our Algora page https://console.algora.io/org/teamhanko
I'd propose you take a look at passkey, which allow for a very convenient, but privacy-friendly alternative to social SSO.
You can even combine social SSO with passkeys. Then users could sign up to your sites with one click through Google or Apple, but any subsequent login can happen between you and the user with a passkey. That's how we are doing things at hanko.io
It’s a passkey-first authentication solution for websites and mobile apps.
Passkeys are WebAuthn "discoverable credentials", meaning they contain a user identifier as well as a private key for signing.
When a site fully supports passkeys, you are able to sign in to your account without having to enter a username, just by using your site-specific passkey (e.g. https://www.passkeys.io).
GitHub's current implementation is based on pre-passkey WebAuthn that allows you to add a non-discoverable credential as 2nd factor. To sign in, you still need to enter your username, your password, and then get prompted for your WebAuthn credential, which can be stored on a physical security key, but also on your devices via the platform authenticator capability (Windows Hello, Touch ID, ...).
So, while GitHub's current 2nd-factor WebAuthn implementation (as awesome as it is) is not "passkey", I'm sure they will be among the first bigger websites to launch full passkey capabilities on their login page pretty soon.
You can go with either self-hosted or cloud. Cloud is free for up to 100 users.
If you have any questions along the way: https://www.hanko.io/community
With that being said, we (or someone else) may reintroduce magic links as another login alternative of Hanko though, because we also think that it is a better UX to click a link than to type a code.
In any case, our take is that the importance of the fallback auth method will diminish over time due to the omnipresence of passkey support.
See also: https://github.com/teamhanko/hanko/discussions/342
Email codes are just the fallback auth method in case no passkeys are supported on the device or the user has lost access to the passkeys. In real world scenarios, this may be secure enough, or fallback authentication could be disabled completely, or secured with Security Keys or other 2FA methods, depending on the use case.