Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
Something you use to prove your identity to a service: a secret you know, a device you hold, or a trait of your body. In everyday use, usually an authenticator app that makes one-time codes.
To authenticate is to prove you are who you say you are. The authenticator is the thing that does the proving. A password is an authenticator you know, a phone that makes codes or a security key is one you have, and a fingerprint is one you are. Standards use the word precisely. NIST's digital identity guidelines describe an authenticator as something the claimant possesses and controls that is used to authenticate. In WebAuthn, an authenticator is the cryptographic entity a browser uses to make and use public-key credentials, such as a security key or a passkey provider. In everyday speech, "authenticator" most often means an authenticator app.
A short code, usually 6 digits, that an authenticator app computes from a shared secret and the current time and that changes every 30 seconds.
A W3C standard that lets websites sign users in with public-key credentials held by an authenticator instead of with passwords.
A discoverable WebAuthn credential that lets you sign in to a site with a fingerprint, face or screen lock instead of a password.
Multi-factor authentication that cannot be completed by a fake website, because the proof is bound to the real site's address.
Our expert team can help you leverage Authenticator in your project.
Get Free Consultation