Your visitors sign in with a passkey, an email link, or a quick scan from their phone, approve once, and come back signed in — over standard OpenID Connect. No passwords to store, phish, or leak.
WordPress plugin live on wordpress.org · Drupal · Shopify customer accounts · any OIDC client
A visitor clicks Sign in with ZapQR on your login page.
Face ID or Touch ID via passkey, an email magic link — or a QR scan from their phone when the screen can’t do either: TVs, kiosks, cars.
A clear consent screen shows exactly what your site receives: their verified email. Nothing else.
Back on your site, signed in. No password ever existed for anyone to steal.
Nothing to breach. Your database never holds a password for these users.
Phishing-resistant. Passkeys are bound to auth.zapqr.ai — a fake login page gets nothing.
Verified emails. Every account is email-verified before your site ever sees it.
You stay in control. Self-serve credentials, one-click secret rotation, and sign-out that round-trips (RP-initiated logout).
New customer accounts accept your own OIDC provider — connect ZapQR.
The standard openid_connect module works out of the box.
Ghost, Discourse, Grafana, Nextcloud, your own app — if it speaks OIDC, it works.
A password manager with a built-in 2FA authenticator, QR autofill, and a breach scanner — and the home for your ZapQR passkeys, served straight into Safari on iOS and into any app on Android. iCloud Keychain works too; the app gives you more.
Free to download. Requires iOS 17.0 or Android 8.0 and later.
Authorization-code flow with PKCE, refresh tokens, RP-initiated logout. Get a Client ID and Secret self-serve — no sales call, no SDK.