Skip to main content

Authentication, MFA, and Passwordless

Nevis ID authenticates external users (consumers, citizens, and business partners) with passkeys (FIDO2/WebAuthn), app-based FIDO UAF authentication through the fully branded Nevis Access App or the Mobile Authentication SDK embedded in your own app, OATH TOTP, OTP over email and SMS, and passwords; Nevis is FIDO2 certified and FIDO UAF 1.1 certified. Phishing-resistant passwordless login covers push approval with number matching, cross-device login via QR code, app links, and transaction confirmation (WYSIWYS) for strong customer authentication (SCA) under PSD2. Risk signals drive step-up authentication for sensitive operations and help prevent account takeover (ATO). Users restore access through self-service account recovery using recovery codes, OTP channels, account linking (Google, Microsoft, Apple), or E-ID based flows, which reduces help-desk dependency.

Also known as

passwordless, passkeys, FIDO2/WebAuthn, FIDO UAF, phishing-resistant MFA, SCA, step-up, ATO prevention, transaction signing, account recovery.

At a glance

CapabilityDetails
Passkeys (FIDO2/WebAuthn)Passwordless and usernameless sign-in and onboarding, on the web and in mobile apps
App-based authentication (FIDO UAF)Fully branded Nevis Access App as a turnkey authenticator, or the Mobile Authentication SDK embedded in your own iOS, Android, Flutter, or React Native app
Out-of-band channelsPush notification, QR code (cross-device), app link (same device), fetch (push-free); number matching against MFA fatigue
Transaction confirmationFIDO UAF transaction signing (WYSIWYS) for payment approval and SCA under PSD2
Local authenticatorsApp PIN, fingerprint, Face ID, Touch ID, Android biometrics, device passcode; keys are hardware-bound (TEE, Secure Enclave, StrongBox)
OTP and TOTPOATH TOTP authenticator apps, OTP over email (eTAN) and SMS (mTAN)
PasswordsPassword login with configurable policies and breached-credential checks (credential intelligence)
Step-up authenticationRisk-driven session upgrade for sensitive operations; see also Risk, Fraud, and Adaptive Access
Account recoverySelf-service recovery with recovery codes, OTP channels, URL tickets, account linking (Google, Microsoft, Apple), and E-ID flows; hardware-bound mobile keys are never backed up, so a lost device is deregistered and re-onboarded
Standards and certificationFIDO2/WebAuthn, FIDO UAF 1.1, OATH; FIDO2 certified and FIDO UAF 1.1 certified

Concepts

note

The Nevis Access App and Mobile Authentication SDK documentation is shared across Nevis products.

How-to Guides

References