Phishing-resistant authentication overview

Why there's no password or OTP code for a phishing page to capture in the first place.

Updated September 14, 2026 · 1 min read

"Phishing-resistant" describes an authentication design where there's no reusable secret — no password, no OTP code, no session token typed into a form — for a fake page to capture and reuse. PTERI's device-key, challenge-response model is built this way from the ground up; see why passwordless for the problem this solves and how authentication works for the exact mechanics.

What makes it phishing-resistant, specifically

  • The private key never leaves your device — there's nothing to type, so nothing for a phishing page to ask for
  • Every challenge is single-use and short-lived, so even a captured challenge–response exchange can't be replayed later or elsewhere
  • A signature is scoped to the exact action it approves — see how authorization works — so a signature obtained under false pretenses for one action can't be repurposed for another

Rolling it out

For an existing application adding this model, see integrating PTERI into your application and the legacy application integration guide if you're not starting from scratch.

If something goes wrong

See "challenge expired" or "invalid signature" for the two most common failure messages, and recovering account access if a device is lost.

Still stuck?

Ask Kai about this article, or open a ticket with our team.

Submit a ticket