Updates · 2026-03-01
Introducing PasskeyBridge: Identity Security as a Service
By J. W. Bouckaert
The reason we built this
Every identity-aware application faces the same problem: what happens after a threat signal arrives? How do you verify that a user is who they claim to be once a SIM-swap, port-out, or device-compromise event lands in your queue? How do you bind identity to a person, not a password?
Traditional identity providers handle the front door—login, MFA, session issuance. They do not handle what happens at the side door. PasskeyBridge does. We answer the post-detection question with a unified Identity Threat Response as a Service (ITRaaS) platform built on three composable pillars.
The three pillars
Pillar I: Signal ingest & threat response
Point your carrier webhook at your unique PasskeyBridge endpoint. Every payload is verified with HMAC-SHA256, normalized into one of our canonical signal types, matched against your configured playbooks, and dispatched to ordered response actions—all inside the one request. See how we close the gap.
- Multi-provider signal ingest: Vonage Number Insight V2, Twilio Verify + Lookup, Sinch Verification, and arbitrary signed webhooks. Compared in The Carrier Signal Landscape in 2026.
- Canonical signal types covering SIM swap, port-out, device change, fraud alerts, call forwarding, SS7 anomalies, and identity verification results
- Configurable playbooks with retry policies and webhook callbacks—build one in 10 minutes
- Circuit-breaker resilience so a single carrier outage never cascades into a total verification failure
Pillar II: Verifiable credentials
Native W3C Verifiable Credentials 2.0 verification with optional BYOK for OpenID4VP and OIDC4VC presentation flows. Integrate with walt.id, Trinsic, or any conformant issuer. Users prove identity through cryptographic proofs without exposing personal data.
- Selective disclosure via SD-JWT
- Trusted issuer allowlists per tenant
- Credential type filtering and presentation definition support
- Scoped digital delegates for AI agents
Pillar III: Biometric binding
WebAuthn / FIDO2 passkeys bind user identity to device-level biometrics and hardware-backed authenticators. PasskeyBridge manages the full passkey lifecycle: registration, authentication, and parametric revocation when a threat signal triggers automatic credential freezing.
- Hardware-backed authenticator support (TPM, Secure Enclave, FIDO2 keys)
- Multi-device passkey sync awareness
- Automatic revocation on compromise signals
- Hybrid post-quantum signing across the assertion path—see Hybrid Signatures in Practice
Available today
- All three pillars in production, exposed through one API surface
- Real-time tenant dashboard with overview, events, keys, playbooks, identity, usage, posture, and a growing set of advanced security and observability tabs (CAEP, BLAST, cached proofs, runtime guard, agent trust, and more)
- Scoped AI agent delegates for agentic workflows and A2A trust
- Social recovery with M-of-N guardian thresholds
- SOC 2 Type II observation window open, evidence-pack reusable across audit controls for identity APIs, built on a zero-PII architecture
- Public, real-traffic API playground that runs the live /health probe from your own browser and reports the p50, p95 and p99 it observes
Pricing
PasskeyBridge ships three plans. Authoritative limits and Stripe-billed prices live on the pricing page; the figures here are accurate at publication.
- Starter—Free. 100 signals/month, 1 playbook, 1 webhook source, 7-day event retention, community support.
- Pro—$99/mo. 10,000 signals/month, all three pillars, native VC engine, batch VP token verification, 10 playbooks, 5 webhook sources, 90-day retention, 24h email SLA. 7-day free trial.
- Enterprise—$499/mo. Everything in Pro plus agentic identity delegation, A2A trust, agent behavioral trust scoring, BLAST shadow proxy, cached offline trust proofs, and 1,000,000 signals/month included, then $0.04 per signal. 7-day free trial.
Per-seat add-on licenses for Pillar II and Pillar III are quoted per 1,000 users; current rates and bundle discounts live on the pricing page and the FAQ.
Further reading
- W3C Verifiable Credentials Data Model 2.0—The canonical specification underpinning Pillar II.
- W3C WebAuthn Level 3—The platform standard underpinning Pillar III.
- Identity Threat Response in 2026: Why ITRaaS Is the New Category—How we frame the category PasskeyBridge defines.
- The Carrier Signal Landscape in 2026—Provider-by-provider comparison of the signals that feed Pillar I.