OpenID Connect identity provider

The passwordless sign-in button for your site.

Your visitors sign in with a passkey, an email link, or a quick scan from their phone, approve once, and come back signed in — over standard OpenID Connect. No passwords to store, phish, or leak.

WordPress plugin live on wordpress.org · Drupal · Shopify customer accounts · any OIDC client

ZapQR
Sign in to Northloom Store
with your ZapQR account
Email
Continue with passkey
or
Email me a sign-in link
Secured by ZapQR · auth.zapqr.ai
How it works

Four steps. Zero passwords.

1

They click your button

A visitor clicks Sign in with ZapQR on your login page.

2

They prove it's them

Face ID or Touch ID via passkey, an email magic link — or a QR scan from their phone when the screen can’t do either: TVs, kiosks, cars.

3

They approve — once

A clear consent screen shows exactly what your site receives: their verified email. Nothing else.

4

They're in

Back on your site, signed in. No password ever existed for anyone to steal.

Why sites switch

Nothing to breach. Your database never holds a password for these users.

Phishing-resistant. Passkeys are bound to auth.zapqr.ai — a fake login page gets nothing.

Verified emails. Every account is email-verified before your site ever sees it.

You stay in control. Self-serve credentials, one-click secret rotation, and sign-out that round-trips (RP-initiated logout).

Works with
wordpress

WordPress

Install the ZapQR Login plugin from the directory, paste two credentials, done.

shopify

Shopify

New customer accounts accept your own OIDC provider — connect ZapQR.

drupal

Drupal

The standard openid_connect module works out of the box.

custom

Anything OIDC

Ghost, Discourse, Grafana, Nextcloud, your own app — if it speaks OIDC, it works.

The companion app

Your passkeys live in ZapQR for iPhone and Android

A password manager with a built-in 2FA authenticator, QR autofill, and a breach scanner — and the home for your ZapQR passkeys, served straight into Safari on iOS and into any app on Android. iCloud Keychain works too; the app gives you more.

Free to download. Requires iOS 17.0 or Android 8.0 and later.

Security Score 98
Strong passwords
2FA enabled
Passkeys synced
No breaches found
For developers

Standard OIDC, ten-minute setup

Authorization-code flow with PKCE, refresh tokens, RP-initiated logout. Get a Client ID and Secret self-serve — no sales call, no SDK.

# discovery
https://auth.zapqr.ai/.well-known/openid-configuration
# scopes
openid email profile offline_access
# your credentials
https://auth.zapqr.ai/account