How it works

How AuthLN ends attacks before login completes

Legitimate users sign in passwordless in about a second and never feel a thing. Everyone else hits a cost they can't justify — so the attack stops being worth attempting. Here's exactly how.

What it does

One gate. Two outcomes. No false positives.

AuthLN adds a single factor to every login: an economic gate in front of your existing identity provider. Real users clear it instantly with a passkey. Everyone else has to pay — and almost never does. The result is less noise, cleaner signal, and a record of every attempt.

Legitimate users never feel it

A passkey clears the gate in about 1.2 seconds. No payment, no extra step, nothing to learn.

Attackers stop at the cost

The only way past is to fund a Lightning invoice. Most walk away the moment they see it.

Every attempt is evidence

Who tried, when, from where, and how it ended — logged per user, ready for your team.

The flow

Five steps — under a second for real users

01

Login starts

A user signs in through the identity provider you already run — Okta, Microsoft Entra ID, or Google.

02

The gate appears

AuthLN places a Lightning invoice in front of the attempt. Real users never see it.

03

Passkey confirms

A device-bound passkey in the Secure Enclave proves it's really them — no password to phish.

04

Invoice clears

Authorized users cancel it instantly and pay nothing. Everyone else has to fund it from their own wallet.

05

In, or on record

Real users are in. Unauthorized attempts are stopped, logged, and traced back to their source.

Two paths

The same gate, opposite experiences

Authorized users

In about 1.2 seconds — and they never pay.

  • Present a device-bound passkey from the hardware enclave.
  • The invoice clears automatically — no payment, nothing to see.
  • No passwords, so nothing to phish or replay.

Everyone else

Pay real money to even try — most don't.

  • With no passkey, the only way forward is to fund the invoice.
  • Bots can't pay an invoice, so they fail silently.
  • The rare few who pay are still denied — and traced.
Then your policy takes over. Every unauthorized attempt is captured — payment, origin, credential, and timing — and your security policy decides the response: alert your SOC, isolate the pattern, or escalate to incident response.

We don't block attacks — we end them.

Authorized users log in normally. Attackers pay for every attempt — until they stop trying. See it running in front of your own identity provider.

Schedule a Demo