Back to the blog
beveiliginginloggenpasskey
New

Signing in without a password: which options are there?

Typing a password has long stopped being the only way into your customer portal. Five methods are now available and you choose yourself which one you use. How do they differ, and which is the best fit for you?

Your password always stays

Worth knowing before you switch anything on: none of the new methods replaces your password, they sit alongside it. Create a passkey on your laptop and that laptop breaks? You still get in with your password. On top of that we recommend everyone to enable two-step verification: a six-digit code from an authenticator app on your phone, in addition to the password. It is the cheapest protection there is, and it keeps out anyone who only has your password.

Signing in with a passkey

A passkey is a digital key that stays on your own device. Instead of typing something, you unlock your phone or laptop the way you are used to — with a fingerprint, your face or the device PIN — and that is enough. No password ever travels across the internet, and the key itself never leaves your device.

That is also what makes a passkey resistant to phishing. It only works on the real website: if a fake e-mail leads you to an imitated sign-in page, there is simply nothing to hand over. And because you already unlocked your device to use that key, the portal no longer asks for a code from your authenticator app afterwards — that step is already included. You can happily create several passkeys, one on your laptop and one on your phone for instance. Sold or lost a device? Then you remove that one key in your settings; the rest keep working.

A sign-in code in your mailbox

If you would rather not type a password on a device that is not yours, switch on the sign-in code by e-mail. You enter your e-mail address, we send you a six-digit code and it stays valid for ten minutes. After five wrong attempts it expires and you request a new one.

This method relies entirely on your mailbox, which is why two-step verification does stay in place here: otherwise anyone who reaches your mailbox would be straight into your account. For the same reason, a session like that cannot change security settings. Want to remove a passkey or switch a method? Then sign in again with your password or passkey first.

With your Google or Microsoft account

Does your company work with Google Workspace or Microsoft 365? Then link that account to your login once. After that you click the Google or Microsoft button on the sign-in page and you are in, with no extra password to remember. You can unlink at any time, and your regular login keeps working in the meantime.

With your own organisation's sign-in

Larger organisations usually work with their own identity provider — Okta, Microsoft Entra ID or anything else that speaks OpenID Connect. You connect it yourself. Your colleagues then sign in the way they do for all their other work applications, and whoever leaves the company loses access the moment their account there is closed. A new colleague automatically gets a login the first time they sign in, so there is nothing to create in advance. We do first ask for proof that the e-mail domain is yours, through a DNS record — otherwise someone else could claim your domain.

One sign-in for all our services

All our brands authenticate in the same central place. Signed in at SMSBOX and moving on to one of our other services? You get in there without signing in again. It works the same way round: you sign out everywhere in one go.

What should you choose?

For most people this is the strongest combination: a passkey on the device you work with every day, your password with two-step verification as a backup, and the e-mail code only if you often have to sign in from changing devices. Managing a team? Then your own identity provider is worth it: you arrange access in one place instead of per user.

You will find everything in the customer portal under Login & security. Want to know more about signing in with Google, Microsoft or your own identity provider? Have a look at our Single Sign-On page or get in touch.

#sign in without password#passkey#passwordless login#two-step verification#secure login#e-mail sign-in code
Trust Guard Security Scanned
Call us
Send an email