Skip to content
AspirecoStart
All answers

Web & mobile apps

What is passwordless sign-in, and should a business app use it?

The short answer

Passwordless sign-in lets people log in with a one-time code or link sent to their email or phone instead of a password. For most business apps it is the better default: nothing to forget or reuse, and no password database to leak.

Updated

How it works

The user enters their email, receives a short-lived code, and types it in. The server checks the code and issues a session token the app uses from then on. There is no stored password to check against — or to steal.

Why it suits business apps

Field staff and occasional users are the people most likely to forget passwords and reuse weak ones. A code by email removes the reset flow entirely.

What we built

For Shopflooring, our own storefront, we shipped a dedicated mobile API with six-digit email sign-in, bearer tokens and push notifications, so the native Android client shares one source of truth with the web store. Passwordless auth is a standard part of the apps we build, in from the first commit.

When to add more

Where the stakes are higher, add a second factor on top of the code rather than falling back to passwords.

Asked next

Is an emailed sign-in code as secure as a password?

It avoids the biggest password risks — reuse and leaked password databases — because each code is short-lived and single-use. Its security then rests on the email account, so users who matter should protect that mailbox well.

What happens if a user loses access to their email?

They need another verified way back in, such as an administrator re-issuing access. That recovery path is designed at the start, not added after the first locked-out user.