Passwords created an entire layer of friction that developers and users have learned to accept as normal.
Users forget them, reuse them, reset them, get phished for them, and depend on recovery flows when something goes wrong.
Developers inherit the other side of that problem: credential storage, password resets, MFA enrollment, account recovery, session security, and all the support overhead surrounding it.
That’s why I started building VeriLink.
VeriLink is a passwordless SSO platform that lets developers authenticate users through secure, one-time magic links instead of traditional passwords.
The larger goal isn’t just to remove a password field. I want to reduce how much authentication infrastructure developers need to build and maintain while making sign-in simpler for users.
I’m currently building out the developer experience, SSO architecture, recovery flows, and OAuth/OIDC integrations.
I’m especially interested in feedback from other founders and developers:
When you’ve implemented authentication in your own product, what part caused the most friction — initial integration, account recovery, MFA, identity providers, or something else?
I’m building VeriLink in public, so criticism and architectural questions are absolutely welcome.