How it works
The user enters their email, receives a short-lived code, and types it in. The server checks the code and issues a session token the app uses from then on. There is no stored password to check against — or to steal.
Why it suits business apps
Field staff and occasional users are the people most likely to forget passwords and reuse weak ones. A code by email removes the reset flow entirely.
What we built
For Shopflooring, our own storefront, we shipped a dedicated mobile API with six-digit email sign-in, bearer tokens and push notifications, so the native Android client shares one source of truth with the web store. Passwordless auth is a standard part of the apps we build, in from the first commit.
When to add more
Where the stakes are higher, add a second factor on top of the code rather than falling back to passwords.