Self-hosted passkeys for mobile apps. Built on TwinShield. No third-party lock-in. Hardware-protected transactions.
Operated by MailBIT • Backed by TwinShield technology
A passkey replaces the password. Instead of a secret your users type — one that can be guessed, stolen or phished — their phone proves who they are. Nothing to remember, and nothing in your database worth stealing.
The private half of the key never leaves the phone — your servers only ever hold the public half. Even a full database breach leaves an attacker nothing usable.
Each key is tied to your exact app and domain. A counterfeit site or cloned app can ask all it likes — without the genuine key, there is nothing for it to capture or replay.
Users authenticate with the Face ID, fingerprint or PIN they already trust to unlock their phone — no one-time codes to wait for, and no passwords to reset.
Stronger security and a smoother login at once — the rare upgrade that costs your users nothing to adopt.
No phishing, no credential stuffing, no reuse breaches — there is no password to steal in the first place.
Keys are generated and held inside the device's security hardware — out of reach of malware on the phone and breaches on your servers alike.
One tap with Face ID or a fingerprint. Nothing to type, nothing to wait for, nothing to forget or reset.
Built on FIDO and WebAuthn, supported across Apple, Google and Microsoft — proven, and free of proprietary lock-in.
| HOSTED PASSKEY PROVIDERS | PASSKEY.IN.TH | |
|---|---|---|
| 01Where the passkey lives | ✕The provider's servers | ✓Your own infrastructure |
| 02Relying party & domain | ✕Registered to the vendor | ✓Registered to your own domain |
| 03Who holds the credential | ✕A third party | ✓Your database — your environment |
| 04Vendor lock-in | ✕High — re-enrol every user | ✓None — the passkeys are yours |
A passkey proves who signed in — but the transaction that follows isn't signed by anyone. Secure SMS puts a hardware signature on each transaction at the source, so it can't be forged, intercepted, or AIT-pumped.
Each OTP carries a hardware signature from the registered device — bots can't trigger it, attackers can't fake it.
No app, no enrolment, on every phone. It covers recovery, onboarding, and the devices a passkey can't.
The same protection extends beyond SMS to WhatsApp and LINE — secured identically.
Carrier-grade Thai delivery built for high-risk financial apps. High deliverability, transparent pricing.
Security should never be a cost barrier
Secure OTP billed per successful delivery
Tell us about your app and we'll set up a Passkey.in.th trial on your own infrastructure. Prefer to chat? Reach us on WhatsApp or LINE.