
Technology
Managed IAM services
Identity and Access Management (IAM) systems control who gets access to what. WWPass handles the part most of them leave exposed: the authentication step itself. No username. No password. No credential an attacker can steal, phish, or replay.

Technology
Managed IAM services
Identity and Access Management (IAM) systems control who gets access to what. WWPass handles the part most of them leave exposed: the authentication step itself. No username. No password. No credential an attacker can steal, phish, or replay.

Technology
Managed IAM services
Identity and Access Management (IAM) systems control who gets access to what. WWPass handles the part most of them leave exposed: the authentication step itself. No username. No password. No credential an attacker can steal, phish, or replay.
The credential gap in IAM
An IAM system can enforce the most granular access policies in the world and still be undone by one stolen password. If a stolen credential gets through the front door, everything behind it is at risk regardless of the policies in place.
WWPass addresses that gap directly. Authentication no longer involves a username or password. It involves a cryptographic key held by the user and a key held by the service provider. Only their combination opens access.
WWPass does not replace IAM. It replaces what IAM authenticates against.
Existing directories, policies, roles, and access controls remain in place. WWPass removes the username and password from the authentication event those systems manage.
For IAM teams this means the policies already built continue to apply, but the front door is no longer a credential an attacker can steal. WWPass also separates the identification and authorization processes entirely, eliminating the risks associated with human-manageable credentials at the architecture level.
How it compares to conventional approaches
Conventional IAM | WWPass | |
Login model | Username and password, often with OTP or push | One cryptographic key, no username or password |
Where secrets live | Centralized directory or password store | Data encrypted and split across multiple nodes |
Account recovery | Password reset links, security questions | Secure credential restoration through the same distributed model |
Attack surface | Every login, factor, and reset flow | No shared secret entered, transmitted, or stored |
What it integrates with
— WWPass integrates with existing Identity and Access Management and SSO infrastructure through SAML, OAuth2, and OIDC. Directory integration bridges existing Active Directory and LDAP environments without requiring migration.
— For SSO, WWPass supports multiple deployment configurations: Cloud-based (lightweight): SAML and OpenID Connect connectors via manage.wwpass.com. WWPass handles authentication only. The SSO layer is managed by the existing platform such as Google Workspace, Auth0, or Okta.
— On-premises: WWPass Authentication running on a dedicated SSO server based on Gluu or Keycloak. More advanced in functionality, building on those platforms' existing SSO capabilities.
— Cloud (WWPass-hosted): the on-premises configuration hosted by WWPass, for organizations that need full functionality without managing their own SSO infrastructure.
— Additional confirmed integrations: IBM Security Access Manager, Fortinet, Cisco, Juniper, OpenVPN for VPN access, and Windows and VMware for remote desktop. WWPass software development kits/WWPass SDKs are available for most common programming languages for teams that prefer to self-integrate.
Zero Trust and compliance alignment
When used with a hardware WWPass Key and PIN or biometric, authentication reaches Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B, the highest level defined. This satisfies the access control requirements of NIST SP 800-207 Zero Trust Architecture directly.
For AAL3 environments, WWPass supports continuous authentication: ongoing monitoring of connection parameters including IP address range, time of day, browser type and version, and other behavioral characteristics. Where parameters fall outside defined ranges, the system provides alerts and, where appropriate, automatic access rights revocation. This audit capability sits at the storage server level rather than the authentication network, so security requirements can be tuned to the specific application without changing the authentication layer.
This authentication model maps directly to the access control and ICT risk requirements addressed by DORA, NIS2, HIPAA, NIST 800-63, and CMMC.
Deployment
WWPass deploys as a cloud service or as a fully self-hosted system, including in air-gapped environments where no external network connectivity is permitted. WWPass engineers are available for customized integration support where needed.
Frequently asked questions
Q: Does WWPass replace our existing IAM system?
A: No. WWPass replaces the authentication step within an IAM system, not the system itself. Existing directories, policies, and access controls remain in place. WWPass separates the identification and authorization processes at the architecture level, removing credential-based risk without changing what the rest of the IAM system manages.
Q: What directory services does WWPass support?
A: WWPass SSO includes directory integration for Active Directory and LDAP environments, bridging existing user directories without requiring migration.
Q: What protocols does WWPass support?
A: Confirmed integrations use SAML, OAuth2, OIDC, and CAS. WWPass SSO is built on open-source Gluu and supports the same protocol set.
Q: Can WWPass cover VPN and remote access as well as applications?
A: Yes. WWPass integrates with Fortinet, Cisco, Juniper, and OpenVPN for VPN access, and supports Windows and VMware remote desktop environments. One WWPass Key covers all of these alongside web and SaaS application access.
Q: What assurance level does WWPass authentication reach?
A: With a hardware key and PIN or biometric, WWPass reaches AAL3 as defined in NIST SP 800-63B, the highest level defined. This also satisfies NIST SP 800-207 Zero Trust Architecture requirements.
Q: How is WWPass deployed?
A: As a cloud service or fully self-hosted, including air-gapped environments. WWPass engineers are available for customized integration assistance where needed.
The credential gap in IAM
An IAM system can enforce the most granular access policies in the world and still be undone by one stolen password. If a stolen credential gets through the front door, everything behind it is at risk regardless of the policies in place.
WWPass addresses that gap directly. Authentication no longer involves a username or password. It involves a cryptographic key held by the user and a key held by the service provider. Only their combination opens access.
WWPass does not replace IAM. It replaces what IAM authenticates against.
Existing directories, policies, roles, and access controls remain in place. WWPass removes the username and password from the authentication event those systems manage.
For IAM teams this means the policies already built continue to apply, but the front door is no longer a credential an attacker can steal. WWPass also separates the identification and authorization processes entirely, eliminating the risks associated with human-manageable credentials at the architecture level.
How it compares to conventional approaches
Conventional IAM | WWPass | |
Login model | Username and password, often with OTP or push | One cryptographic key, no username or password |
Where secrets live | Centralized directory or password store | Data encrypted and split across multiple nodes |
Account recovery | Password reset links, security questions | Secure credential restoration through the same distributed model |
Attack surface | Every login, factor, and reset flow | No shared secret entered, transmitted, or stored |
What it integrates with
— WWPass integrates with existing Identity and Access Management and SSO infrastructure through SAML, OAuth2, and OIDC. Directory integration bridges existing Active Directory and LDAP environments without requiring migration.
— For SSO, WWPass supports multiple deployment configurations: Cloud-based (lightweight): SAML and OpenID Connect connectors via manage.wwpass.com. WWPass handles authentication only. The SSO layer is managed by the existing platform such as Google Workspace, Auth0, or Okta.
— On-premises: WWPass Authentication running on a dedicated SSO server based on Gluu or Keycloak. More advanced in functionality, building on those platforms' existing SSO capabilities.
— Cloud (WWPass-hosted): the on-premises configuration hosted by WWPass, for organizations that need full functionality without managing their own SSO infrastructure.
— Additional confirmed integrations: IBM Security Access Manager, Fortinet, Cisco, Juniper, OpenVPN for VPN access, and Windows and VMware for remote desktop. WWPass software development kits/WWPass SDKs are available for most common programming languages for teams that prefer to self-integrate.
Zero Trust and compliance alignment
When used with a hardware WWPass Key and PIN or biometric, authentication reaches Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B, the highest level defined. This satisfies the access control requirements of NIST SP 800-207 Zero Trust Architecture directly.
For AAL3 environments, WWPass supports continuous authentication: ongoing monitoring of connection parameters including IP address range, time of day, browser type and version, and other behavioral characteristics. Where parameters fall outside defined ranges, the system provides alerts and, where appropriate, automatic access rights revocation. This audit capability sits at the storage server level rather than the authentication network, so security requirements can be tuned to the specific application without changing the authentication layer.
This authentication model maps directly to the access control and ICT risk requirements addressed by DORA, NIS2, HIPAA, NIST 800-63, and CMMC.
Deployment
WWPass deploys as a cloud service or as a fully self-hosted system, including in air-gapped environments where no external network connectivity is permitted. WWPass engineers are available for customized integration support where needed.
Frequently asked questions
Q: Does WWPass replace our existing IAM system?
A: No. WWPass replaces the authentication step within an IAM system, not the system itself. Existing directories, policies, and access controls remain in place. WWPass separates the identification and authorization processes at the architecture level, removing credential-based risk without changing what the rest of the IAM system manages.
Q: What directory services does WWPass support?
A: WWPass SSO includes directory integration for Active Directory and LDAP environments, bridging existing user directories without requiring migration.
Q: What protocols does WWPass support?
A: Confirmed integrations use SAML, OAuth2, OIDC, and CAS. WWPass SSO is built on open-source Gluu and supports the same protocol set.
Q: Can WWPass cover VPN and remote access as well as applications?
A: Yes. WWPass integrates with Fortinet, Cisco, Juniper, and OpenVPN for VPN access, and supports Windows and VMware remote desktop environments. One WWPass Key covers all of these alongside web and SaaS application access.
Q: What assurance level does WWPass authentication reach?
A: With a hardware key and PIN or biometric, WWPass reaches AAL3 as defined in NIST SP 800-63B, the highest level defined. This also satisfies NIST SP 800-207 Zero Trust Architecture requirements.
Q: How is WWPass deployed?
A: As a cloud service or fully self-hosted, including air-gapped environments. WWPass engineers are available for customized integration assistance where needed.
The credential gap in IAM
An IAM system can enforce the most granular access policies in the world and still be undone by one stolen password. If a stolen credential gets through the front door, everything behind it is at risk regardless of the policies in place.
WWPass addresses that gap directly. Authentication no longer involves a username or password. It involves a cryptographic key held by the user and a key held by the service provider. Only their combination opens access.
WWPass does not replace IAM. It replaces what IAM authenticates against.
Existing directories, policies, roles, and access controls remain in place. WWPass removes the username and password from the authentication event those systems manage.
For IAM teams this means the policies already built continue to apply, but the front door is no longer a credential an attacker can steal. WWPass also separates the identification and authorization processes entirely, eliminating the risks associated with human-manageable credentials at the architecture level.
How it compares to conventional approaches
Conventional IAM | WWPass | |
Login model | Username and password, often with OTP or push | One cryptographic key, no username or password |
Where secrets live | Centralized directory or password store | Data encrypted and split across multiple nodes |
Account recovery | Password reset links, security questions | Secure credential restoration through the same distributed model |
Attack surface | Every login, factor, and reset flow | No shared secret entered, transmitted, or stored |
What it integrates with
— WWPass integrates with existing Identity and Access Management and SSO infrastructure through SAML, OAuth2, and OIDC. Directory integration bridges existing Active Directory and LDAP environments without requiring migration.
— For SSO, WWPass supports multiple deployment configurations: Cloud-based (lightweight): SAML and OpenID Connect connectors via manage.wwpass.com. WWPass handles authentication only. The SSO layer is managed by the existing platform such as Google Workspace, Auth0, or Okta.
— On-premises: WWPass Authentication running on a dedicated SSO server based on Gluu or Keycloak. More advanced in functionality, building on those platforms' existing SSO capabilities.
— Cloud (WWPass-hosted): the on-premises configuration hosted by WWPass, for organizations that need full functionality without managing their own SSO infrastructure.
— Additional confirmed integrations: IBM Security Access Manager, Fortinet, Cisco, Juniper, OpenVPN for VPN access, and Windows and VMware for remote desktop. WWPass software development kits/WWPass SDKs are available for most common programming languages for teams that prefer to self-integrate.
Zero Trust and compliance alignment
When used with a hardware WWPass Key and PIN or biometric, authentication reaches Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63B, the highest level defined. This satisfies the access control requirements of NIST SP 800-207 Zero Trust Architecture directly.
For AAL3 environments, WWPass supports continuous authentication: ongoing monitoring of connection parameters including IP address range, time of day, browser type and version, and other behavioral characteristics. Where parameters fall outside defined ranges, the system provides alerts and, where appropriate, automatic access rights revocation. This audit capability sits at the storage server level rather than the authentication network, so security requirements can be tuned to the specific application without changing the authentication layer.
This authentication model maps directly to the access control and ICT risk requirements addressed by DORA, NIS2, HIPAA, NIST 800-63, and CMMC.
Deployment
WWPass deploys as a cloud service or as a fully self-hosted system, including in air-gapped environments where no external network connectivity is permitted. WWPass engineers are available for customized integration support where needed.
Frequently asked questions
Q: Does WWPass replace our existing IAM system?
A: No. WWPass replaces the authentication step within an IAM system, not the system itself. Existing directories, policies, and access controls remain in place. WWPass separates the identification and authorization processes at the architecture level, removing credential-based risk without changing what the rest of the IAM system manages.
Q: What directory services does WWPass support?
A: WWPass SSO includes directory integration for Active Directory and LDAP environments, bridging existing user directories without requiring migration.
Q: What protocols does WWPass support?
A: Confirmed integrations use SAML, OAuth2, OIDC, and CAS. WWPass SSO is built on open-source Gluu and supports the same protocol set.
Q: Can WWPass cover VPN and remote access as well as applications?
A: Yes. WWPass integrates with Fortinet, Cisco, Juniper, and OpenVPN for VPN access, and supports Windows and VMware remote desktop environments. One WWPass Key covers all of these alongside web and SaaS application access.
Q: What assurance level does WWPass authentication reach?
A: With a hardware key and PIN or biometric, WWPass reaches AAL3 as defined in NIST SP 800-63B, the highest level defined. This also satisfies NIST SP 800-207 Zero Trust Architecture requirements.
Q: How is WWPass deployed?
A: As a cloud service or fully self-hosted, including air-gapped environments. WWPass engineers are available for customized integration assistance where needed.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.

Get WWPass
Download the WWPass Key app and test authentication without a username or password.
