Direct methods
The user owns the credential outright. No third party can revoke or suspend access.- Passkey: Biometric or passkey-based login based on the WebAuthn standard. Phishing-resistant and device-bound.
- Wallets: External wallet login via Sign-In With Ethereum and Sign-In With Solana.
Delegated methods
A third party controls the credential. Account access depends on that provider remaining available.- OAuth and socials: Social login with Google, Apple, Twitter, Discord, GitHub, LinkedIn, Spotify, Telegram, Farcaster, and more.
- Email or SMS: Passwordless login via a one-time passcode sent to a user’s email address or phone number.

