> For the complete documentation index, see [llms.txt](https://stephen-tsoi.gitbook.io/stephen-tsoi-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://stephen-tsoi.gitbook.io/stephen-tsoi-docs/security/beyond-otp-designing-authentication-for-a-global-mobile-first-world.md).

# 🔐 Beyond OTP: Designing Authentication for a Global, Mobile-First World

A global authentication blueprint explaining how to combine Passkeys for phishing-resistant logins with OAuth for secure enterprise-scale API authorization.

When designing authentication for browsers and mobile applications, one question inevitably comes up:

### "How should we authenticate users securely and reliably across different regions and devices?" <a href="#ember65" id="ember65"></a>

Many organizations still rely on One-Time Passwords (OTP), but real-world implementation often reveals significant challenges:

* 📧 OTP via email: Delivery is not guaranteed and meeting strict SLA requirements can be difficult.
* 📱 OTP via SMS or voice call: Services may be restricted, blocked, or unreliable in certain countries and regions.
* 🔔 Mobile push notifications: No universal solution exists across all mobile operating systems and ecosystems.

So how do we design an authentication strategy that balances **security, usability, and global reach**?

### 🌐 OAuth: Authorization at Scale <a href="#ember70" id="ember70"></a>

OAuth is primarily an **authorization framework**, typically working alongside an Identity Provider (IdP) that handles authentication.

#### How OAuth Works <a href="#ember72" id="ember72"></a>

* The user or client is authenticated by the IdP.
* A short-lived access token is issued.
* APIs and backend systems validate the token.
* Access is controlled using scopes and claims.

**Best For**

* API security
* System-to-system integration
* Delegated authorization

#### Challenges <a href="#ember76" id="ember76"></a>

⚠️ Authentication often still relies on OTP, passwords, or other verification mechanisms.

⚠️ Identity data management introduces operational overhead:

* User profiles, email addresses, and phone numbers must be stored and protected.
* Privacy, compliance, and regulatory requirements become increasingly complex.

<br>

### 🔑 Passkeys: Passwordless Authentication <a href="#ember81" id="ember81"></a>

Passkeys are an **authentication method**, not an authorization mechanism.

Built on **FIDO2 and WebAuthn**, passkeys leverage public-key cryptography to eliminate passwords while significantly reducing phishing risks.

#### How Passkeys Work <a href="#ember84" id="ember84"></a>

* A public/private key pair is created during registration.
* The private key remains securely stored on the user's device.
* The private key cannot be extracted or shared.
* Authentication is performed using biometrics or a device PIN.

**Best For**

* Human user authentication
* Passwordless user experiences
* Phishing-resistant login journeys

#### Challenges <a href="#ember88" id="ember88"></a>

⚠️ Cross-platform portability can still create friction.

⚠️ User experience may depend on cloud synchronization services provided by platform vendors.

⚠️ Device and OS support varies across markets and user segments.

⚠️ Passkeys do not address system-to-system authentication scenarios.

<br>

### 🧩 The Key Difference <a href="#ember94" id="ember94"></a>

Many conversations compare OAuth and Passkeys as competing technologies.

They are not.

* **OAuth answers:** *"What can this user or application access?"*
* **Passkeys answer:** *"How can we securely prove this person is who they claim to be?"*

The strongest architecture often combines both:

🔑 **Passkey** for secure, passwordless user authentication

🌐 **OAuth** for authorization, API access, and backend integration

### 💡 Final Thought <a href="#ember101" id="ember101"></a>

One of the most overlooked authentication challenges emerges when serving customers across different regions, particularly in China.

SMS delivery restrictions, regulatory considerations, and unique mobile ecosystem dynamics can significantly impact traditional OTP strategies.

The reality is that **there is no universal authentication solution today**.

### How is your organization addressing authentication beyond OTP? 🚀 <a href="#ember106" id="ember106"></a>

<figure><img src="https://media.licdn.com/dms/image/v2/D5612AQHPhkqRRqhD7g/article-inline_image-shrink_1000_1488/B56aAzafhIIsAM-/0/1787568982151?e=1791417600&#x26;v=beta&#x26;t=STHbUFuQwDUXK81Y0b5edt9SXn0jdeQdEsTBGQZHSls" alt="Article content"><figcaption></figcaption></figure>

## 🚀 Let's Connect Beyond GitBook!

If you found this article helpful, you can find more of my technical insights, daily discussions, and deep dives across these platforms:

* **Read more of my work:** Check out my articles on [dev.to](https://dev.to/stephen_tsoi_5b2c4055f3a9) and [Hashnode](https://stephentsoi.hashnode.dev/).
* **Join the daily conversation:** Connect with me directly on [LinkedIn](https://www.linkedin.com/in/stephen-tsoi-16309730/).

***

#### 📬 Stay Ahead of the Curve

Enjoyed this piece? I break down complex technical topics into bite-sized, actionable insights every week.

👉 **Subscribe to my** [**LinkedIn Newsletter**](https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7487299517642612736) to never miss an update and get the latest articles delivered straight to your feed!


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://stephen-tsoi.gitbook.io/stephen-tsoi-docs/security/beyond-otp-designing-authentication-for-a-global-mobile-first-world.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
