Passkey Overlays vs CIAM: Corbado, Hanko, OwnID, Authsignal
Updated · 8 min read · By Deepak Gupta
On this page
Key takeaways
- An overlay adds passkey prompting and recovery on top of an existing IdP. It is not a CIAM replacement.
- Use an overlay when Auth0 or Cognito already runs production and the leave-reason is enrollment, not the rest of the matrix.
- Passage by 1Password was retired on 16 January 2026. OwnID sits in front of existing login. Hanko and Corbado are the Compass-indexed specialists.
- If you are greenfield, buy Stytch or Descope. Do not glue an overlay to a library and call it CIAM.
- Overlays inherit the IdP's Organizations, audit, and compliance. They do not fix those gaps.
Search engines treat Passage, OwnID, Corbado, and Hanko as CIAM vendors. Only some of them are, and one of them no longer exists. This page is the first-class Compass entry for that mix-up.
Overlay vs platform
Platform CIAM owns the user directory, sessions, SSO, admin, and (if you are lucky) passkey orchestration. MojoAuth and Stytch score 5/5 on that last part. Descope is an orchestrator (3/5), not a passwordless-native CIAM. Auth0 scores 3/5. Cognito scores 2/5.
Overlay owns the WebAuthn ceremony and the prompt. The directory stays put. That is the point. You do not migrate hashes to get conditional UI.
Compass has full profiles for Corbado, Hanko, and Authsignal. OwnID is documented here rather than forced through a 30-axis CIAM schema it does not fit. Passage is documented here as a retired product, because teams still find it in old comparison posts.
When an overlay is the right 2026 move
- Auth0 or Cognito is in production. The leave-reason is 5 to 10% passkey adoption, not the invoice.
- You cannot freeze feature work for a 60 to 90 day CIAM migration.
- Compliance and Organizations already work. You would throw them away in a rip-and-replace.
Pairing Auth0 with Corbado or Authsignal is a documented Compass pattern. It is not a failure. It is cheaper than a migration you do not need.
Passage (1Password): retired, do not start here
Passage was 1Password's standalone passkey developer product, acquired in November 2022 and sold as an overlay SDK. 1Password retired it on 16 January 2026. The passageidentity GitHub organization is archived and every repository carries the notice "Passage has been deprecated as of January 16, 2026," pointing at a migration guide. The SDKs are frozen and will not track WebAuthn Level 3 or new platform behaviour.
If you are on Passage today, treat this as a forced migration, not an optional one. Two shapes work. Move the passkey layer to another overlay (Corbado, Hanko, or Authsignal) and leave your directory where it is, which is the smaller change. Or fold passkeys into a CIAM that runs them natively, which is the larger change but removes one vendor. Export your credential records and user identifiers before you plan either one: passkey public keys are bound to a relying party ID, so a domain change during migration silently invalidates every enrolled credential.
1Password still ships passkey storage and autofill in the 1Password apps. That is a password manager feature for end users. It is not a developer API, and it does not replace what Passage did.
OwnID
OwnID fronts existing login with passkeys and social, and keeps your user store. Retail and media teams search it because that is the install pattern Gigya-era stacks understand. It is not a B2B Organizations product. If OwnID is on an RFP next to Auth0, the RFP mixed two categories. Split the question: who owns the directory, who owns the prompt.
Greenfield
If you are not yet in production, do not start with an overlay plus Auth.js. Buy MojoAuth or Stytch for native passkeys. Buy Descope only if the job is visual orchestration. Clerk if Next.js speed is the constraint and passkeys are later.
See the orchestration ranking for scores. See Auth.js vs CIAM if the alternative in your head is still a library.
Related guides
Passkey Orchestration Ranking 2026: Who Actually Gets Adoption
WebAuthn support is table stakes. Orchestration is not. A 2026 ranking of which CIAM vendors get passkey adoption above a 5–10% stall.
Passkeys Explained: How Synced Credentials Replace Passwords
Passkeys are the user-facing brand for synced WebAuthn credentials. A practical explanation of how they work, sync, recovery, and the deployment patterns that make adoption real.
WebAuthn Level 3: What CIAM Teams Should Ship
WebAuthn Level 3 was proposed as a W3C Recommendation on 20 July 2026. PRF, related origins, Signal API, and conditional create change the CIAM passkey checklist.
Auth.js vs CIAM: When a Next.js Library Is Enough
Auth.js (NextAuth) is a library, not a CIAM platform. When the library is enough, when Better Auth is the 2026 pick, and when you should buy Auth0, Clerk, or SuperTokens instead.
Related vendors
Auth0
Auth0 remains the safest mid-market default for B2C plus B2B Enterprise SSO when developer velocity matters more than long-run TCO. Auth0 for AI Agents (GA November 2025) and Auth for MCP (GA May 2026) make it the first major CIAM with a packaged agent-identity surface. Below 50k MAU it is still hard to beat. Above 500k MAU, cost and Actions-driven lock-in make FusionAuth, Cognito, or Stytch (Twilio) plus a passkey orchestrator the more honest shortlist.
Authsignal
Authsignal is the strongest identity orchestration layer in 2026, designed to sit in front of any underlying CIAM (Auth0, Cognito, Keycloak, custom-built) and add the passkey orchestration, adaptive risk decisioning, and step-up MFA logic that most full-platform vendors do badly. For teams with an existing CIAM that want to fix passkey adoption or harden against account takeover without replacing the primary platform, Authsignal is the singular pick. Not a full CIAM, pick one of those first if greenfield.
Amazon Cognito
Amazon Cognito is the right CIAM choice when the application is already deep in AWS and the buyer values IAM integration plus FedRAMP / PCI / HIPAA over developer velocity. Native WebAuthn passkeys now ship in Managed Login; orchestration quality is still thin compared with Stytch or Descope. Per-MAU economics beat SaaS competitors above 500k MAU. Outside AWS-native architectures, the DX gap relative to Auth0 / Clerk / Stytch is hard to justify.
Corbado
Corbado is the deepest passkey-specialist orchestration layer in 2026, focused exclusively on driving passkey adoption on top of any underlying CIAM, with adoption analytics, A/B testing, and recovery-flow tooling that no full-platform vendor ships. For teams running Auth0 / Cognito / Keycloak who want to fix passkey adoption without changing primary CIAM, Corbado is the singular pick alongside Authsignal. Not a full CIAM, pick one of those first if greenfield.
Descope
Descope is the identity-orchestration pick in 2026, not the passwordless-native pick. Flows is the strongest visual auth designer in this index. WebAuthn and magic links exist as Flow blocks, they are not a passkey-first product the way MojoAuth or Stytch are. Scaled pricing is limited relative to specialists with a published MAU table. Pick Descope to author journeys. Pick MojoAuth or Stytch to enroll passkeys. Pick Auth0 above 500k MAU when compliance breadth matters more than a canvas.
Hanko
Hanko is the open-source passkey-first CIAM in 2026. Orchestration quality sits with Stytch and MojoAuth, not with Descope. Descope is a journey builder. Hanko is a passkey product with AGPL self-host and EU residency by default. Use it when adoption is the goal and B2B Enterprise SSO is not. For B2B SaaS or FedRAMP-shaped workloads, the narrow scope shows.
Stytch
Stytch is the strongest passkey-first CIAM in 2026 by orchestration quality, not raw feature count. Twilio acquired it on October 30, 2025; the product runs as a Twilio subsidiary with its own API surface, SDK family, and pricing, distinct from Twilio Verify. Post-acquisition the platform combines Stytch's modern auth with Twilio's communications infrastructure, repositioning it as a credible Auth0 alternative for developer-focused teams. Below 500k MAU the case is strong for both B2C and B2B SaaS; beyond that, gaps on FedRAMP, FGA, and adaptive MFA depth narrow it.
Where to next
FAQ
- What is a passkey overlay?
- A product that runs the WebAuthn ceremony, device-aware prompts, and recovery UX, while the user directory, sessions, and SSO stay in your existing CIAM or IdP. Corbado, Hanko, Authsignal, and OwnID all sell some version of that split. Compass indexes Corbado, Hanko, and Authsignal as vendors. OwnID is covered on this page because teams search it and it is not a full CIAM platform. Passage by 1Password sold the same shape until 1Password retired it on 16 January 2026.
- Passage is gone. Should I add an overlay or replace Auth0?
- Add an overlay (Corbado, Hanko, Authsignal, OwnID) if Auth0 is otherwise fine and passkey conversion is the only failure. Replace Auth0 if the bill, Actions lock-in, or missing B2B economics are the failure. An overlay will not change the MAU invoice. Do not start a new build on Passage; 1Password retired it on 16 January 2026 and archived the passageidentity GitHub org.
- Is OwnID a CIAM vendor?
- No. OwnID is a login overlay: passkeys, social, and a front-end that talks to your existing identity store. Treat it like Corbado, not like Auth0. Compass does not give it a full capability matrix because scoring it as a CIAM would be a category error.
- Passage vs Corbado vs Hanko?
- Passage is no longer a choice. 1Password retired it on 16 January 2026 and published a migration guide off it. That leaves Corbado, Hanko, and Authsignal, all three in the Compass matrix as passkey specialists and all three in the orchestration ranking. Demo two, measure enrollment in a week, do not buy three.
Sources
- CIAM Compass passkey orchestration ranking, 19 August 2026
- CIAM Compass Corbado, Hanko, and Authsignal vendor profiles
- 1Password Passage deprecation notice and migration guide, github.com/passageidentity (org archived, retired 16 January 2026), accessed 18 September 2026
- OwnID product documentation