Moon

One key.
Every door.

Moon is the passwordless identity layer for modern products. Ship passkeys, SSO and enterprise ready auth in an afternoon, without ever storing a secret.

Get started Read the security brief
2.4M identitiesverified in the last hour

A billion passwords.
Zero of them yours to keep.

Moon issues cryptographic keys bound to the device, the domain and the user, so credentials never touch your database and never leave the hardware they were born on.

Passkey issued
Zero secrets stored

Passwords are the breach.

Every leaked credential list is a story about a company that thought they could hold a secret. Moon removes the secret from the story.

Passkeys, done properly.

A single sign in flow that spans devices, browsers and platforms. Moon handles fallback, recovery and enterprise policy in one API.

An identity layer
that ships in an afternoon.

Drop in the SDK, connect your directory, and every user in your product gets a key that only they and their device can prove.

2024, retailer breach
17M passwords leaked, 41% reused across services
17M
2023, forum breach
28M credentials sold on dark web, plaintext
28M
2023, SaaS breach
63M rows exfiltrated, MFA bypass via SMS
63M
2022, telecom breach
104M identities exposed, class action ongoing
104M
2022, healthcare breach
11M patients, SSN and DOB exposed
11M
1
User taps sign in
Browser prompts for the device passkey
2
Device signs a challenge
Hardware key, biometric confirmed locally
3
Moon verifies the signature
Public key, no secret leaves the device
4
Session issued
Signed, short lived, ready to use
Active identities
2.4M
↑ 12% this quarter
Passkey coverage
94%
of monthly active users
Sign in latency
142ms
p95, global median
Secrets stored
0
by design, forever
Recent events
priya@northwind.comPasskey enrolled2s ago
rae@constellation.ioSession refreshed8s ago
sena@brightunion.comRecovery completed1m ago

Three quiet promises Moon keeps
that change how you think about auth.

Nothing to steal

Moon never stores a password, a secret, or a phone number. If we were breached tomorrow, the attacker would find nothing worth taking.

Anywhere the user is

iOS, Android, macOS, Windows, Linux, web. Moon handles the passkey handshake across every platform your users actually live on.

Enterprise ready by default

SCIM, SAML, session policy, audit log, per tenant keys. Every plan ships with what compliance would have asked for on day thirty.

Moon removed the entire class of
problems we used to spend a quarter defending against.

Sena ItoHead of Platform, Bright Union

Six lines of code.
A lifetime of not being breached.

Drop in the Moon SDK, mount the sign in component, and every user in your product gets a passkey the first time they land.

app/auth.ts
// One import, one line of setup

import { Moon } from "@vault/client"



const vault = new Moon({ tenant: "acme" })



// Anywhere in your app

const session = await vault.signIn()



// That is the whole flow. No passwords, no reset emails.
Moon SDK 2.0Deployed in production, six hundred teams

Ship auth
this afternoon.

Free up to ten thousand monthly identities. Bring your app, we bring the keys, and the first sign in happens within an hour.