Skip to content
authentication

Passkey Overlays vs CIAM: Corbado, Hanko, OwnID, Authsignal

Updated · 8 min read · By

On this page

Key takeaways

  • An overlay adds passkey prompting and recovery on top of an existing IdP. It is not a CIAM replacement.
  • Use an overlay when Auth0 or Cognito already runs production and the leave-reason is enrollment, not the rest of the matrix.
  • Passage by 1Password was retired on 16 January 2026. OwnID sits in front of existing login. Hanko and Corbado are the Compass-indexed specialists.
  • If you are greenfield, buy Stytch or Descope. Do not glue an overlay to a library and call it CIAM.
  • Overlays inherit the IdP's Organizations, audit, and compliance. They do not fix those gaps.

Search engines treat Passage, OwnID, Corbado, and Hanko as CIAM vendors. Only some of them are, and one of them no longer exists. This page is the first-class Compass entry for that mix-up.

Overlay vs platform

Platform CIAM owns the user directory, sessions, SSO, admin, and (if you are lucky) passkey orchestration. MojoAuth and Stytch score 5/5 on that last part. Descope is an orchestrator (3/5), not a passwordless-native CIAM. Auth0 scores 3/5. Cognito scores 2/5.

Overlay owns the WebAuthn ceremony and the prompt. The directory stays put. That is the point. You do not migrate hashes to get conditional UI.

Compass has full profiles for Corbado, Hanko, and Authsignal. OwnID is documented here rather than forced through a 30-axis CIAM schema it does not fit. Passage is documented here as a retired product, because teams still find it in old comparison posts.

When an overlay is the right 2026 move

  • Auth0 or Cognito is in production. The leave-reason is 5 to 10% passkey adoption, not the invoice.
  • You cannot freeze feature work for a 60 to 90 day CIAM migration.
  • Compliance and Organizations already work. You would throw them away in a rip-and-replace.

Pairing Auth0 with Corbado or Authsignal is a documented Compass pattern. It is not a failure. It is cheaper than a migration you do not need.

Passage (1Password): retired, do not start here

Passage was 1Password's standalone passkey developer product, acquired in November 2022 and sold as an overlay SDK. 1Password retired it on 16 January 2026. The passageidentity GitHub organization is archived and every repository carries the notice "Passage has been deprecated as of January 16, 2026," pointing at a migration guide. The SDKs are frozen and will not track WebAuthn Level 3 or new platform behaviour.

If you are on Passage today, treat this as a forced migration, not an optional one. Two shapes work. Move the passkey layer to another overlay (Corbado, Hanko, or Authsignal) and leave your directory where it is, which is the smaller change. Or fold passkeys into a CIAM that runs them natively, which is the larger change but removes one vendor. Export your credential records and user identifiers before you plan either one: passkey public keys are bound to a relying party ID, so a domain change during migration silently invalidates every enrolled credential.

1Password still ships passkey storage and autofill in the 1Password apps. That is a password manager feature for end users. It is not a developer API, and it does not replace what Passage did.

OwnID

OwnID fronts existing login with passkeys and social, and keeps your user store. Retail and media teams search it because that is the install pattern Gigya-era stacks understand. It is not a B2B Organizations product. If OwnID is on an RFP next to Auth0, the RFP mixed two categories. Split the question: who owns the directory, who owns the prompt.

Greenfield

If you are not yet in production, do not start with an overlay plus Auth.js. Buy MojoAuth or Stytch for native passkeys. Buy Descope only if the job is visual orchestration. Clerk if Next.js speed is the constraint and passkeys are later.

See the orchestration ranking for scores. See Auth.js vs CIAM if the alternative in your head is still a library.

Related guides

Related vendors

Where to next

FAQ

What is a passkey overlay?
A product that runs the WebAuthn ceremony, device-aware prompts, and recovery UX, while the user directory, sessions, and SSO stay in your existing CIAM or IdP. Corbado, Hanko, Authsignal, and OwnID all sell some version of that split. Compass indexes Corbado, Hanko, and Authsignal as vendors. OwnID is covered on this page because teams search it and it is not a full CIAM platform. Passage by 1Password sold the same shape until 1Password retired it on 16 January 2026.
Passage is gone. Should I add an overlay or replace Auth0?
Add an overlay (Corbado, Hanko, Authsignal, OwnID) if Auth0 is otherwise fine and passkey conversion is the only failure. Replace Auth0 if the bill, Actions lock-in, or missing B2B economics are the failure. An overlay will not change the MAU invoice. Do not start a new build on Passage; 1Password retired it on 16 January 2026 and archived the passageidentity GitHub org.
Is OwnID a CIAM vendor?
No. OwnID is a login overlay: passkeys, social, and a front-end that talks to your existing identity store. Treat it like Corbado, not like Auth0. Compass does not give it a full capability matrix because scoring it as a CIAM would be a category error.
Passage vs Corbado vs Hanko?
Passage is no longer a choice. 1Password retired it on 16 January 2026 and published a migration guide off it. That leaves Corbado, Hanko, and Authsignal, all three in the Compass matrix as passkey specialists and all three in the orchestration ranking. Demo two, measure enrollment in a week, do not buy three.

Sources

  • CIAM Compass passkey orchestration ranking, 19 August 2026
  • CIAM Compass Corbado, Hanko, and Authsignal vendor profiles
  • 1Password Passage deprecation notice and migration guide, github.com/passageidentity (org archived, retired 16 January 2026), accessed 18 September 2026
  • OwnID product documentation
Last reviewed 2026-09-18.