A dark wall covered in hundreds of identical brass keys on hooks, one empty hook glowing green

For humans

The average person has 168 accounts that want a password. However many you have, not one of them follows you anywhere. Every new device starts with hours of logging back in to services that already know exactly who you are.

That entire experience is one design mistake, made in 1961 and imitated ever since: the company keeps your identity, and you keep a secret that lets you ask them to use it. Forget the secret and you beg a stranger to let you back into your own life. Know someone else's and you simply are them, no begging required. To the system, the secret is the person.

Why not a password? Why not a passkey?

A password proves only that its sender knows it. And checking it means sending it: the far end has to receive the secret, so it travels every time it is used, across your keyboard, your screen, and the wire. Careful sites scramble it the moment it arrives and never store it readable. That protects their vault, not your trip. Phishing lives on the trip: on a screen, your bank and a picture of your bank are identical, and the secret works wherever it lands. And because nobody can memorize 168 secrets, passwords get reused, so one careless door opens many.

A passkey fixes the trip. It proves without sending the secret: the site receives a signature, never the key. Real progress, honestly. What remains is the key itself, because it is a file, and a file has three fates. If it syncs between your devices, it syncs thru a vendor's cloud, and a copy is as good as the original. If it is locked to one device instead, the device becomes the identity: lose the device, lose yourself. So vendors bridge the gap with account recovery, a door they hold, and whoever can convince the vendor is you.

Sent, copied, or recoverable by strangers. You are none of these things. You cannot be handed over, you do not copy, and there is no support line a stranger can call to become you. Your identity should be built the way you are.

passless turns it the right way around.

How it works, in plain words

You pick a name. Any name at all: slow tide, paper kite, your grandmother's nickname for you. If nobody has claimed it, it is yours. That name, plus the devices you own, is your identity. Nothing is mailed to you, nothing is issued, nobody approves it.

Your devices become you. Add your phone, your laptop, your watch. Each one can act as you. Losing one is losing a gadget, not your life: your other devices carry on, and you turn the lost one off from any of them. You can even set it so a new device needs a person's approval: your son gets a ping, calls you, asks "did you get a new phone?", and taps yes. That is the whole ceremony. No password was involved because no password exists.

You prove who you are exactly once. After that, every service simply recognizes you, the way your dog does. No login screens, no codes texted to you, no "prove you're not a robot." There is no session to expire because there is no session.

Recovery is people, not passwords. When every device is gone, the people who know you vouch you back in: your sister, your oldest friend, faces that recognize yours. Not a call center. Not a reset link. Not security questions an internet stranger can answer by reading your Facebook.

What if a big company builds it? Good. Three rules travel with the protocol, and any version that breaks one is not passless and is not covered by the patent pledge. Your recovery people are yours and you can move them, so no company is ever the only way back in. No company's chip counts as more human than anyone else's, so a verifier cannot tell whose phone answered. Your secret is made on your own device, not in a factory, so nobody has a copy to revoke or hand over. If Apple, Google and your carrier all ship it, your identity works the same on a phone none of them made.

What if someone steals your phone?

Walk it from the thief's side. They hold your hardware, and holding hardware is not being you: the phone will not speak for you. You notice, and any other device of yours turns the stolen one off.

Now give the thief everything and say they get it asserting anyway. The first consequential thing they try, moving your money, adding a device, buying a car as you, does not just go thru. It rings the people you chose, and the call their screens show carries a proof of where it came from: not "this looks like you," but "this came from your hardware," signed by the camera itself. AI can fake your face now. It cannot fake your silicon. So the thief is live, on stolen hardware, facing your sister.

And your sister asks how the dog is doing. What the mechanic said on Tuesday. How your mum's knee is holding up. A stranger who memorized your entire internet fails here, because these answers were never on the internet, and they change every week. A security question is a secret that never changes, which is why it protects nothing. Your life is a secret that never stops changing, which is why it works.

"We'll text you a code to prove you're human"

Typing back a texted code proves exactly one thing: a phone number can receive texts. Notice who received the code: a machine. Warehouses of SIM cards pass "prove you are human" checks all day, by the thousand, while a human with a dead battery fails. It does not prove human. It does not prove one. It does not prove you. It proves you rent a number from a carrier, and it hands the service a number that links your accounts across every database it ever touches.

passless never texts you a code. Your hardware answers with math only your hardware can produce, fresh every time, and the big things wait for humans who know your face. A machine can receive a code. Only your devices can answer your challenge, and only your people can say it is really you.

Can you be two people?

Try it. Claim a second handle on a second phone. Nothing stops you. There is no rule against ten, and there never will be, because a rule would need a ruler and passless does not have one.

But you already know how this goes, because you have carried a work phone. Two chargers on the nightstand. Two pockets, and the buzz you check on the wrong one. The battery that is dead at noon because it spent the weekend in a drawer. People pay extra for a dual-SIM phone just to stop carrying two of everything, and still miss the call. That is the maintenance bill for two phone numbers. Now price two people.

Your sister messages the old you. Your photos split down the middle of your memories. Your paycheck lands on one of you, the mortgage application comes from the other, and the bank only lends to someone whose life adds up in one place. Anyone who has ever posted from the wrong account knows the cold sweat; a second identity is that feeling, permanently, about everything.

A second handle is free. A second life is a second job, unpaid, forever. You will do what every human does: pour everything into the one that is really you, and let the spare gather dust. Nobody forbids the spare. Life just never funds it.

Handles you can claim: no limit. Lives you have to live them with: 1. That is the whole enforcement mechanism, and it cannot be hacked, bribed, or subpoenaed.

What nobody can do to you

The rule is simple: whoever holds the key owns the thing. passless puts the key in your hands and nowhere else.

What you can do today

Install Photon, a free messenger built on passless identity. Pick your name, add a second device the same day, and message people with no phone number, no account, and no company in the middle. It has worked since July 2026 and it works in places with no cell service at all.

Two honest cautions while it is young: until people-based recovery is finished, your devices are the only copies of you, so never be down to one. And your name is first come, first served, so pick something distinctive.

Then add me. You will notice my handle is not printed here. Handles pass between humans, not websites: ask me in person, or get it from someone who already knows me. That is not an inconvenience. That is the system working, and it is why nobody on Earth can spam you.

It is early and it is buggy. Expect bumps. First rides are like that.