Hanko’s cover photo
Hanko

Hanko

Computer and Network Security

The European authentication platform for modern apps. Open source, privacy-first, and built without vendor lock-in.

About us

Quickly integrate Hanko’s APIs and Web Components to get secure and modern user authentication for your apps. From passwords to passkeys, 2FA, and SSO. Finally an auth solution that scales – without locking you in: Migrate your data between self-hosted and Hanko Cloud whenever you want.

Website
https://www.hanko.io
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
Kiel
Type
Privately Held
Founded
2018
Specialties
Authentication-as-a-Service, WebAuthn, Web Authentication, 2FA, MFA, Passwordless Authentication, Biometric Authentication, FIDO2, and Passkeys

Locations

Employees at Hanko

Updates

  • Hanko reposted this

    Sometimes the best technical decisions are driven by your users. Originally, I was heading down the path of rolling my own auth for PitchIn Technologies. But as word of mouth started taking off and interest picked up, I realized my time was better spent building the core product. I looked at the popular auth providers, but I had two hard rules: no vendor lock-in, and no unnecessary infrastructure to self-host and maintain. That led me straight to Hanko. Today, I’m incredibly excited and grateful to share that PitchIn has officially been accepted into the Hanko Startup Program! A massive thank you to the Hanko team for the support. Having a partner like this means I can stay focused on scaling PitchIn and delivering a great experience for everyone waiting to use it. Back to building! 💻✨ #hanko #pitchin #startup #software #softwaredevelopment #crowdfunding

    • No alternative text description for this image
  • Hanko reposted this

    On Easter Sunday, my wife and I were casually talking about password managers. She told me she had discovered, and really liked, that you can now store not only passwords in a password manager, but also 2FA codes and even passkeys. And honestly, I get it. It is incredibly convenient to have everything you need for login in one place: passwords, TOTP secrets, passkeys, autofill, sync across devices. It makes life easier. It reduces friction. And it solves real problems. She had run into exactly the opposite problem before: after changing phones, she could not properly move one 2FA account stored in Microsoft Authenticator. She ended up keeping her old phone around for months just so she could still access that account. That is obviously not a great security or usability story either. But the conversation got me thinking about the tradeoff. If your password, your second factor, and maybe even your passkeys all live in the same vault, then your account security ultimately depends on that one vault staying secure. In many cases, that means: one password. Yes, the account itself may still be protected with 2FA. But from the user’s perspective, the attack surface has changed. If an attacker compromises the password manager, they may get everything needed for login at once. That is very different from a setup where: the password is stored in a password manager the second factor is kept separately in another app or on another device That kind of separation is less convenient, but it also reduces concentration of risk. So is it still 2FA if both factors are stored in the same place? Technically, yes. Practically, it is worth thinking twice. The safest option is often a hardware security key, because it is logically and physically separate. But even that comes with a cost: the most secure factor is useless when it locks out the legitimate user because they do not have it with them when they need it. Security is rarely about absolutes. It is usually about balancing risk, convenience, and recoverability. For individuals and companies alike, this is the real question: How many eggs do you want in one basket? Convenience is valuable. But concentration of risk is real. Curious how others think about this: Do you store passwords, TOTP, and passkeys all in one place? Or do you deliberately keep them separate?

    • Eggs in a basket, representing accounts and credentials.
  • Hanko reposted this

    Yesterday I shared how an email passcode helped me log into IKEA’s kitchen planner on a public computer. That story points to a broader product decision we made at Hanko: Why we chose passcodes over magic links. Magic links sound great on paper. Open email. Click link. Done. But in practice, passcodes solved the same problem with fewer UX issues. The main reason is cross-device usability. A passcode can arrive on your phone while you log in on another machine. That makes it much better for public computers, shared devices, or any situation where you do not want to access your inbox on the same device. Passcodes also keep the login flow in the same tab. No extra browser tab, no broken context, no zombie tabs left behind. And unlike magic links, there is no fragile login URL that might get pre-fetched or invalidated by email clients or email security systems. Yes, passcodes are a bit more manual. Users have to type or paste a code. But that small extra step buys a lot: + better cross-device UX + fewer edge cases + more robust behavior + cleaner browser flow That is why we went with passcodes instead of magic links in Hanko. Sometimes the less flashy option is simply the better product decision. Magic links or passcodes, what has worked better for you?

    • Passcode input during a login flow using Hanko
  • Hanko reposted this

    How a passcode helped me buy an IKEA kitchen: I had been working on our kitchen plan at home over several evenings in IKEA’s online planner. Then on Saturday, I sat down with an IKEA employee at one of their public planning PCs and needed to log in again. I got a one-time passcode by email on my phone, entered it on the public PC, and continued right where I left off. And honestly, that felt exactly right. At a public computer, in front of strangers, I do not want to type a regular password. I probably would not even know it. And for a use case like this, I may not need that account again for months. That is what I find so interesting about email passcodes. Not every account needs a serious long-term credential. Sometimes the user just wants access in the moment, with as little friction as possible. For situations like this, passcodes can be a very good fit. They have some clear advantages: + no reusable password to remember or expose + easy to use on public or shared devices + well suited for temporary or infrequent accounts + straightforward mental model for the user Of course, they also come with tradeoffs: - email delivery can be delayed - emails can land in spam - there is still a context switch to the inbox - entering a code is slightly more manual But in this case, the benefits clearly outweighed the downsides. Sometimes the right login method is not the flashiest one. It is the one that fits the moment.

    • Email with a passcode for signing in to my IKEA account
  • Hanko reposted this

    It doesn’t always have to be “Sign in with Google.” In the Nordics, authentication often looks a bit different. Services like Danish MitID, Norwegian BankID, and Swedish BankID are widely used to log into apps and websites. Not just in B2C, but also in B2B. And there are good reasons for that. These systems don’t just authenticate a user. They provide a verified identity. That means: - stronger assurance of who the user actually is - reduced fraud and account misuse - higher trust in user actions and transactions - often better alignment with regulatory requirements For one of our customers in Sweden, StepLock, supporting BankID wasn’t a “nice to have”. It’s what users expect. So we extended Hanko to support it. We added the ability to configure custom OpenID Connect providers, so you can integrate any identity system that speaks OIDC. Including national eID schemes like BankID. One provider per scheme. Fully configurable. The result: Users can choose the login methods they already know and trust. And teams stay flexible beyond the usual set of preconfigured providers. The nice part is that this isn’t limited to BankID. If it supports OIDC, you can plug it into Hanko.

    • No alternative text description for this image
  • Hanko reposted this

    A highly skilled full-stack developer I work closely with is currently available for new projects. Expertise in Go, Java, Typescript and more. Fluent in German and English. Remote work preferred, on-site possible in Kiel, Germany. Feel free to reach out or share with your network!

  • Hanko reposted this

    Ever had your password stolen? Phishing and credential theft are still two of the biggest threats online. But we already have a cure. Phishing works because people are tricked into typing credentials on fake sites. Data breaches are dangerous because attackers can steal and crack password hashes offline. And if those passwords are reused, the damage multiplies fast. Passkeys fix this. There are no secrets to phish, nothing stored server-side to steal, and they only work on the site or app where they were created. Phishing and credential theft become a thing of the past. When we started building Hanko, we went all-in on passkeys. Passwords came more than a year later, only to give developers flexibility. For us, passkeys aren’t a feature. They’re the foundation for a safer internet.

    • No alternative text description for this image
  • Hanko reposted this

    How a shower thought turned into Hanko 10 years ago, standing in the shower and thinking about a student thesis project I was supervising at the time, I asked myself this simple question: "What annoys me most about the internet every single day?" The answer was obvious: passwords. I had maybe 5 or 6 that I reused across every account. I knew it wasn’t secure. But password managers were still clunky back then, and I kept forgetting, resetting, and getting frustrated. So I thought: There must be a better way. That’s when the idea hit me: We all carry our phones everywhere. So why not just use the phone itself to prove who I am? Together with the student, we built a prototype: ➡️ When logging in, I’d get a push notification ➡️ I’d see the account and website ➡️ And just approve or reject the login The UX felt so good that we kept going after the thesis ended. That prototype became the Hanko Authenticator App — the very first step of what is now Hanko. Fast forward to today: the app still exists and is in use by customers, but Hanko has evolved far beyond that first idea. With the open-source Hanko project, we now provide developers with a complete authentication system — with passkeys at its core. And our mission hasn’t changed: ✨ Reduce the dependency on passwords ✨ Enable secure login experiences everywhere What started as a shower thought has turned into a journey I’m still deeply passionate about. Here's the promo video we made back then, long before MS Authenticator or banking apps had this:

  • Hanko reposted this

    How we came up with the name Hanko Way before passkeys had a name, we were already building with them. Why? Because we’ve always believed that authentication based on asymmetric cryptography is just so much better than passwords. At the heart of it: cryptographic signatures—you prove you have a private key without revealing it. That’s what makes passkeys awesome. So when we needed a name for a company building modern authentication tools, we kept circling back to one thing: signatures. After some deep-dive googling and translating, we came across the Japanese word for signature: Hanko. It had a nice ring to it. And hanko.io was available. Instant yes. Turns out, a Hanko is more than a word: It’s a physical stamp that people in Japan use to sign official documents. Instead of scribbling your name, you leave your personalized stamp. While we’re not in the digital contract business (looking at you, Documenso, Inc. 👋), our system handles cryptographic signatures every time someone logs in. Still counts, right? Even our logo was inspired by a traditional Hanko stamp. Color, shape, the whole thing. And yeah, we eventually bought hanko.com too. The domain move is just a matter of time. We don’t have Japanese roots, but we love the story behind the name and think it fits us perfectly. What’s your “how we named our startup” story? Drop it below 👇 #startups #branding #passkeys #authentication #founderstory #devtools

    • A Hanko stamp

Similar pages

Browse jobs