Stytch Passwords is a re-imagination of the legacy auth method, retrofitted with nimbler breach detection, smarter strength assessments, safe account deduplication and a simpler password reset flow.
Hi Product Hunt 👋,
We’re the founders of Stytch, a modern identity and access management platform. My co-founder, Reed, and I met at Plaid back in 2017 -- during our time there, we both worked on the user authentication features that millions of people use to connect their bank accounts to apps like Venmo, Coinbase, and Robinhood. While working on these projects, we experienced first-hand how frustrating it is to build authentication flows. In addition to being complicated, resource-intensive, and error-prone to build in-house, we saw a fundamental issue with the fact that the oldest and most common form of authentication (Passwords) poses significant security and user experience risks.
We founded Stytch to elevate both the developer and end-user experience of customer authentication. Historically, it’s been too difficult to build exceptional authentication experiences – and given how critical sign-up and login is to companies (it’s a customer’s first touchpoint, a major conversion lever, and the way you protect customers’ sensitive data), we wanted to reimagine what the developer and customer experience could look like when it comes to authentication.
When founding Stytch in 2020, we started by building out a suite of passwordless authentication options (biometrics, magic links, passcodes, social logins, etc.), and today, we’re excited to introduce a modern upgrade to the oldest form of online authentication: passwords. With our new passwords product, we’ve innovated from the ground up to uplevel security and user experience.
Here’s what Stytch’s solution has to offer:
👀 Breach detection: password reuse opens the possibility of credential stuffing attacks. Stytch integrates with HaveIBeenPwnd and prevents users from setting passwords that are present in their dataset of nearly 12 billion compromised credentials. Every time someone logs in with a password, Stytch checks HaveIBeenPwnd to see if those credentials have been compromised since last authentication and triggers a password reset if a breach is detected.
💪 Strength assessment: in the face of password overload, users default to using easy-to-guess passwords. Stytch uses Dropbox’s zxcvbn password strength estimator, which provides a flexible strength assessment based on how resistant a password is to modern password guessing techniques. This feature is designed to make picking a strong password easy for humans to generate and hard for robots to guess.
👯♀️ Safe account de-duplication: Stytch de-duplicates accounts by email regardless of the authentication method. This allows users to change which authentication option they are using to log in to an app without accidentally creating a new account (e.g. a password user can switch to sign in via Google OAuth) or being forced to re-authenticate with the same method originally used.
👪 More human-centric password reset: when an end user triggers a password reset, most of the time they really just want to access their account, not change their password. With Stytch, customers have the option to integrate a traditional password-reset email OR integrate a password reset powered by Email Magic Links for a more seamless experience. We’re building our password-reset email template to be more human-centric, focusing more on UX and conversions than traditional password-reset flows.
In addition to these upgrades to password-based authentication, Stytch is a full identity and access management platform. Alongside our passwords product, you can integrate authorization, multi-factor authentication, passwordless auth, and more!
If you want to learn more about our Passwords product, check out our documentation here: https://stytch.com/docs/passwords
Reed, myself and the rest of the team would love to hear your feedback!
@jelamb Congratulations on the launch! Tell me, do you have a ready-made secure solution for browser extensions? I know it's a small market, but right now, it's empty.
@yankovichv thank you! we don't have any guides on how to do this but it is easy to do with either our js sdk or direct api, if you want to email support@stytch.com, someone can help you get integrated!
The features you mention i need to use different product/tools for different task most of the time. You are giving all in one kind of product.I would love to give it a try. Good luck bro
It took me a minute and some math to figure out this pricing 😂 but best i can tell its free for up to 1,000 users a month (or 2,000 if you refer a friend?) But this looks like a great tool. I'm going to try this out on my next tool that i want to incorporate Auth with. I've been planning to use Next.js for auth but i don't always need next.js so it might actually be easier to use something like this! Congrats on the launch!
@britt_joiner it's $.10 per monthly active user with $100 credits to get you started so that would be 1000 users in one month or can be spread out over many months with less monthly active users. If you have any questions on pricing, feel free to reach out to support@stytch.com and we can work with you! We have some examples and demos using next.js so easy to integrate within that stack or any other! Let us know if you have any questions as you explore more, we'd love to help get you up and running!
@jelamb ah intresting, i see, so it's first 1,000 users, not per month. Got it. Makes sense since you explained but admittedly i found the pricing page confusing - just a bit of feedback. Super cool though and im planning to play around with this for my next app I build with Auth!
I’ve been using Stytch for one of my projects. I must say the API is particularly well designed. A breath of fresh air when compared to some other competing auth services. Congrats on the launch!
Congrats on the launch, really like the UI 🙌 I have a question, how does it differ from next-auth or other libraries that offer similar developer experience, as I see that some features such as magic links, session management, etc overlap?
@eraldo_forgoli great question! with our product you get everything out of the box (like that beautiful ui!), we also handle things like email deliverability for you to make sure that email magic links land front and center in your users' inbox. we invest heavily in building great user experiences and managing the headache that auth can cause both you and your users.
Vowel