Your phone is the key.
No codes to type. NearKey is a two‑factor provider that uses the phone already in your pocket. Enter your password; the phone nearby signs the login over Bluetooth and your browser relays the proof. No SMS, no six digits, no app‑switching.
How a login happens
Four steps, one signature, sixty seconds. The dashboard stays locked until the last one.
-
Password
You enter your password. The server opens a pending login; nothing protected is readable yet.
-
Challenge
The server issues a single‑use challenge bound to this session and sends it to your enrolled phone. It expires in 60 seconds.
-
Signature
Your phone signs the challenge with a key that stays in your phone’s secure storage, then advertises the proof over Bluetooth LE.
-
Verified
Your browser reads the signed proof and relays it. The server checks it once, marks the login complete and your apps open.
Refreshing resumes the server‑confirmed step. Changing the URL never grants a factor.
Honest about what a Bluetooth key proves.
Security claims should be as narrow as the mechanism. Here is exactly what a completed NearKey login tells the server, and what it doesn't.
It proves
- The enrolled phone's private key signed this exact challenge, nonce and session.
- The challenge was issued by the server, not by the browser or the phone.
- Each proof is accepted once and only within its 60‑second window.
- A password alone cannot replace an enrolled phone or skip verification.
It doesn't prove
- Distance. Bluetooth LE doesn't measure proximity or stop a relay attack.
- Consent. Signatures are automatic in this demo; explicit phone approval is deferred.
- Hardware backing. Key protection depends on the device; a secure element isn't guaranteed.
The authenticator lives on the phone you already carry.
Enroll once: the browser shows a setup QR, you scan it in NearKey Authenticator, review the server address and tap Enroll phone. From then on, verification runs in the background whenever a login is pending.
- Private key generated and kept in your phone’s secure storage; only the public key leaves the phone.
- Pairing survives server restarts. Sessions and app lists are reset on purpose.
- Replace a phone from the dashboard: the old one stays enrolled until the new one finishes.
Try it in two minutes.
Sign in with the demo account, enroll a phone, and watch the key land.
Open the demoDemo scope: Mac Chromium with Web Bluetooth, one account, one phone with BLE advertising. Credentials are in the README.
Sign in
Phone setup
Checking session…
Connect your phone
Preparing QR code…
Trying again automatically.
Scan the QR code to get started
Install NearKey on your phone, then scan this QR code in the app.
Enter details manually
Verifying phone
Your apps
Connected apps
0 appsNo apps yet.