Passwordless sign-in, registration and approvals through the messengers your users already trust.
A person opens your app on a desktop, points their phone camera at the QR code on screen, and confirms in Telegram, WhatsApp, MAX or e-mail. No password, no SMS code, no CAPTCHA, and no separate authenticator app to install.
Veriqa is a ready-made authentication layer built around standard OpenID Connect, with native OpenIddict integration for .NET. It extends your existing authentication stack instead of replacing it — much like a social login provider plugs into a modern IAM system. In a typical integration there is no new client-side code to write: you enable and configure it on the server side.
- Passwordless sign-in and registration for web and desktop apps — one familiar action instead of a password, a code and a chain of screens.
- Sign-in plus channel linking in one action — the user signs in, and your product gains a verified, active messenger channel for notifications, approvals and service scenarios.
- Second factor, step-up and action approvals — a sensitive operation is confirmed with a single tap in the user's own messenger, on a surface your app does not have to own.
- Account recovery through a linked trusted channel instead of a chain of e-mails and codes.
- Lead capture without CAPTCHA — a visitor verifies themselves in seconds, and you get a verified contact rather than a dead address from a form.
- A sign-in is a transaction with explicit state, a defined lifetime and a single outcome. It survives a change of device, expires on its own, is idempotent to repeats, and is recorded in the audit trail.
- Channel adapters — Telegram, WhatsApp, MAX and e-mail out of the box, enabled through configuration. A channel of your own requires no changes to the core and does not have to be .NET: it can be an external service over HTTP, or a bot you already run.
- Any stack, standard OIDC. On .NET, Veriqa integrates natively with OpenIddict. Everywhere else — Node, Java, Python, Go, PHP — it behaves as a standard OpenID Connect provider. End-to-end sign-in can be integrated with WordPress, Drupal, Joomla, TYPO3 and Bitrix without changes to their core.
- Configuration all the way down — tokens, channels, sign-in page text and branding, policies, limits and audit behavior, with layered ownership and a defined resolution order. One installation can serve many projects and bots.
- The audit trail follows your rules and can be switched off entirely. Identities are always masked, and tokens are written neither to logs nor to the audit trail — by construction, not as a setting you have to remember.
- .NET 10, shipped as NuGet packages, or as a standalone server in Docker. Storage can be in memory, EF Core-backed databases such as PostgreSQL and MySQL, or Redis. The sign-in page is plain JavaScript with no framework and no external runtime dependencies.
- Self-hosted — run Veriqa inside your perimeter, on-premise or in your own cloud, integrated with the authentication system you already operate. In standalone mode your application needs zero Veriqa packages: it speaks standard OIDC to the server, so your application's SBOM carries no BSL components.
- Veriqa Cloud — for sites and products without authentication infrastructure of their own: integrate at the application or page level without deploying or maintaining the Veriqa server yourself.
Veriqa complements passkeys, messenger widgets and SMS rather than replacing them, and it is worth saying plainly where it stops: confirmation rests on the user's trusted channel and on the API of that channel's platform.
For scenarios where that trust model fits, this is a strong and convenient authentication step — but it is not cryptographic proof of intent, and a messenger does not become a hardware security module. Where the risk model demands more, more is needed.
Veriqa is fair source (source available). The server core is licensed under the Business Source License 1.1 with a generous free-use grant, and every released version automatically becomes Apache 2.0 two years after its release. Samples are MIT.
Production use is free for organizations with annual gross revenue under US $1M and total capital raised under US $3M. For non-profits, the threshold is an annual budget under US $1M. Commercial SaaS use is included.
Above those thresholds, a commercial license applies. There is no license key and no telemetry — eligibility is self-assessed.
- Site and live demo — veriqa.app
- Documentation — veriqa.app/docs
- Questions, pilots and commercial licensing — devs@veriqa.app