The world’s first proximity login
You’re already logged in.
Walk up to your computer and the website signs you in. No tapping, no codes, no prompts to approve — just your phone in your pocket, within a range you set.
Zero interaction. Not fewer taps — none.
Every other second factor asks you to do something. Proximity login asks nothing, because your phone answers the challenge for you.
Instant by default
The login completes while the page is still loading. There is no prompt to wait for and nothing to approve.
Your phone stays in your pocket
Bluetooth Low Energy handles the handshake locally, so you never take your phone out or unlock it to sign in.
A range you control
Set how close is close enough. Step outside that range and the session locks itself behind you.
Watch it race a push prompt
Same login, same moment. One side waits for a notification, types a code, and approves a prompt. The other side is already working.
Proximity login versus a standard push-based authenticator, recorded in real time.
How it works
The website sends a cryptographic challenge that never touches the internet. It travels across your own desk — browser to desktop app to phone over Bluetooth — and comes back signed.
The website
Issues a cryptographic challenge the moment the page opens.
JavaScript
A few lines in the page hand the challenge to the local app.
Desktop app
Relays it straight to your phone over Bluetooth Low Energy.
Your phone
Signs the challenge with hardware-backed keys and sends it back. You’re in.
The entire exchange happens on your desk over Bluetooth. Nothing is routed through a push service, so there is no notification to intercept and no server to take down.
DEPLOYMENT PATH
Add Allthenticate where your employees already sign in.
Your SAML identity provider remains the source of truth. App assignments, conditional access, groups, and audit trails continue to live in Okta, Entra ID, Google Workspace, or whichever IdP you already operate.
COVERAGE
Every SAML-backed business app can inherit proximity login.
Dashboards, HR systems, finance tools, admin consoles, developer apps, data platforms, and custom internal software all keep their current SSO entry point — the login moment just becomes invisible.
Designed for identity teams: no app-by-app rebuilds, no rip-and-replace migration, no new employee habit to train.
SAML NATIVE

A better login changes the workday.
People don’t notice security when it works this naturally — they just keep moving.
BUSINESS ROI
Less login drag. More actual work.
When authentication disappears into the background, employees get back to the tools they opened in the first place. The payoff is simple: fewer interruptions, happier teams, and less time spent supporting access problems.
01
Increase productivity
Remove repeated MFA prompts and password resets from the daily flow, especially for employees who move between internal apps all day.
02
Make security feel effortless
Employees get the security their company needs without the constant cognitive tax of codes, approvals, and app switching.
03
Lower support and recovery costs
Reducing lockouts and manual authentication friction means fewer access tickets, fewer resets, and less time spent helping people get back into tools they already use.
On mobile, the challenge rides in the link
When you’re browsing on the phone itself, there’s no desktop in the middle. We embed the cryptographic challenge directly into a deeplink that only the phone doing the browsing can open.
The link is bound to that browsing session, so a copied URL is useless anywhere else. Tap through and the app answers the challenge with the same hardware-backed key it uses over Bluetooth.
Mobile browser requests a login
Challenge is embedded in a session-bound deeplink
Only that phone can open it — the app signs and returns it
Signed in, same tab
How it compares
Every other approach still needs you in the loop. That’s the part attackers exploit.
Capability
Allthenticate
Yubico
Duo
Microsoft Authenticator
Interaction required to sign in
None at all
Touch the key
Approve a push
Approve and type a number
Phone can stay in your pocket
Yes
No key to insert
No — you unlock it to approve
No — you unlock it to approve
Works with the phone offline
Yes — Bluetooth, on your desk
Yes
No — needs a push
No — needs a push
Prompt bombing possible
No — there is nothing to approve
No
Yes
Reduced, not removed
Credential can be phished
No — bound to the origin, never leaves your desk
No
Yes — you can approve an attacker’s prompt
Yes — you can approve an attacker’s prompt
Extra hardware to carry
None
A key for every device and port
None
None
Locks the session when you walk away
Yes, automatically
No
No
No
Two whole classes of attack, gone
Prompt bombing and phishing both depend on a human deciding something under pressure. Remove the decision and the attacks have nothing to work with.
No prompt to bomb
MFA fatigue works by spamming approval requests until someone taps accept just to make it stop. Proximity login never sends one. There is no notification, no accept button, and no way to wear you down — the challenge is answered by your phone’s secure hardware, not by your patience.
Nothing worth stealing
Phishing needs a secret you can be tricked into handing over. There isn’t one here: no password, no code, no copyable link. The challenge is cryptographically bound to the real site and travels over Bluetooth on your own desk, so a lookalike page has nothing to capture and no way to relay it.
