Auth and identity · Comparison
Magic link vs OTP vs passkeys vs social login
Four ways to let people in without asking them to invent a password. They differ in how many steps they take, what they cost to run and how well they stand up to phishing.
4 options · 8 questions side by side · updated
| Compare | Magic link | OTP | Passkeys | Social login |
|---|---|---|---|---|
| How it works | Click a link sent by email | Type a short code from SMS, email or an app | Unlock with a fingerprint, face or PIN | Approve on Google, Apple, GitHub or similar |
| Steps for the user | Switch to the inbox and click | Wait for the code and type it | One tap or glance | A couple of clicks |
| Phishing resistance | Medium: links can be forwarded or intercepted | Low: codes can be typed into fake sites | High: only works on the real domain | Medium: as strong as the provider account |
| Running cost | One email per sign-in | Free by app or email; SMS costs per message | Free | Free |
| Setup effort | Email sender, tokens and expiry | Code storage, expiry and rate limits | A WebAuthn library or a provider that supports it | A developer app with each provider |
| On a new device | Works wherever the inbox is open | Works anywhere the code arrives | Synced passkey, or a QR scan with a phone | Works after signing in to the provider |
| Depends on | Email arriving quickly | The phone network or inbox | A recent device or password manager | Each provider's rules and uptime |
| Best for | Occasional sign-ins and B2B tools | Phone-first apps and second factors | Returning users on recent devices | Consumer apps that want quick sign-up |
How to choose between Magic link, OTP, Passkeys and Social login
- Pick social login for quick sign-up in consumer apps, with one other method for people who do not use those accounts.
- Pick passkeys when phishing resistance matters, and offer them after the first sign-in rather than as the only way in.
- Pick magic links or email codes for occasional sign-ins, and SMS codes where the phone number is the main identity.
The options
- Magic linkA way to sign in without a password: the person types their email address and the app sends a one-time link that signs them in when clicked.
- OTPA short code, usually six digits, that works once and expires within minutes. It is sent by SMS or email, or generated by an authenticator app, to prove a person controls that phone, inbox or device.
- PasskeysA replacement for passwords: the device creates a unique key for each website and signs in with a fingerprint, face scan or screen lock PIN, with nothing to type or remember.
- Social loginThe standard that lets a person give an app limited access to another service without sharing their password, and the basis of 'Sign in with Google', 'Sign in with Apple' and similar buttons.
More comparisons
- Sessions vs JWTBoth keep a person signed in after they log in. A session keeps the facts on the server and gives the browser a random key; a JWT packs the facts into a signed token that the client carries around.
- Supabase Auth vs Firebase Auth vs Clerk vs Auth.js vs Auth0Five common ways to add sign-in without building it from scratch. Two come bundled with a backend platform, two are dedicated hosted services, and one is a library that runs inside your own app. MAU means monthly active users.
- Node.js vs Deno vs BunThree runtimes for JavaScript and TypeScript on the server. Much of the same code runs on all three; they differ in built-in tools, security defaults, speed and how long each has been used in production.
- Express vs Fastify vs HonoThree JavaScript web frameworks with a similar feel. Express is the long-standing default, Fastify focuses on throughput and structure, and Hono is built on web standards so it can run almost anywhere.
- FastAPI vs Django vs FlaskThree widely used Python web frameworks. Django includes almost everything, Flask includes almost nothing, and FastAPI focuses on typed, self-documenting APIs.
- REST vs GraphQL vs tRPC vs gRPCFour ways for apps and services to ask a backend for data. They differ in who can call them, how strictly the contract is typed, and what travels over the wire.
Crafted in the dark. Shipped to the world.
Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.