KavachOS is open source. Cloud launching soon.
kavachOS

·HUMAN SESSIONS

Passwordless,
by default.

Passkeys, magic links, OAuth, SAML. Every modern auth method, one API. Your users stop memorizing passwords. You stop reporting breaches.

Use passkey for KavachOS
Touch ID required for user_alice@acme.co
Cancel
Continue

The last password you'll ever ship

Every password is a future breach.

The average human reuses six passwords across their digital life. Passkeys end that.

01

Passkeys, first-class.

WebAuthn with FIDO2 is the default. Touch ID, Face ID, and Windows Hello all work through one API. Magic link is the fallback when the platform can't do biometrics.

Use passkey for KavachOS
Touch ID required for user_alice@acme.co
Cancel
Continue

02

Every OAuth provider, ready.

27 providers pre-wired. Google, GitHub, Apple, Microsoft, LinkedIn, Discord, Slack, plus regional players. One adapter interface to add your own in 40 lines.

oauth · providers27 wired
GGoogle
GGitHub
AApple
MMicrosoft
LLinkedIn
DDiscord
SSlack
NNotion
FFigma
+ 18 moreadd your own →

03

Session rotation you don't think about.

Cookies rotate on privilege change, IP jump, or stale inactivity. CSRF double-submit out of the box. Revocation propagates edge-wide in under 500ms.

session · user_alicerotating
14:02:18
session created
chrome · macOS · SFO
14:02:19
rotation key issued
TTL 4h · HMAC-SHA256
14:45:02
privilege change
admin scope added
14:45:02
session rotated
old cookie revoked
15:12:44
IP changed
SFO → NYC · flagged
15:12:44
MFA re-challenge
WebAuthn · passed

04

MFA and recovery that don't suck.

TOTP, WebAuthn as second factor, SMS for last-resort recovery. Codes hashed like passwords with Argon2id. Impersonation guards prevent admin-panel account takeover.

recovery codeshashed · argon2id
A4F2-9K7M-QR3X
8H2N-PB5V-W9CT
X7LD-FM3Y-KN8B
Q2TR-6VJH-Z5AP
9CBW-3DKN-M4FY
UH5L-2XPQ-R7VG
5 of 6 remaining · rotated 12d ago

Ship real auth this afternoon.

Install the library. Wire your adapter. Your users stop thinking about passwords.

MIT licensed · TypeScript · Edge-native · Zero dependencies