← Back to all sparks
H

Hanko

INFRA · APIS
Velocity0.0

Open-source authentication platform providing passkeys, passwordless login, and MFA with full data ownership

Hanko ships Firebase migration support and tightens session management — targeting auth stack replacements.

authenticationpasskeysidentitysecurityopen-source
Current state
Hanko is a passkey-first authentication platform available as open-source self-hosted or cloud-managed. Monthly releases show consistent refinement across the auth stack: stronger passcode options, inactivity-based session termination, session token transparency, device trust handling improvements, and expanded OAuth/OIDC integration. The June 2026 Firebase Scrypt hash import signals an active effort to reduce friction for teams migrating away from Firebase Auth.
Where it's heading
The consistent themes across these releases are session management hardening, migration tooling, and auth protocol breadth. Custom OAuth connections, user metadata via Admin API, Firebase import, and OIDC updates together sketch a product trying to compete with established auth platforms (Auth0, Clerk) on flexibility and self-hostability. The monthly cadence is execution-focused — incremental improvements rather than architectural shifts.
Prediction
The next likely moves are broader migration support (other providers beyond Firebase, e.g. Supabase Auth or Cognito) and enterprise session controls such as SAML or organization-level device trust policies. Custom OAuth was the groundwork; SAML is the common next ask.

Recent moves

  1. 3mo ago

    June 2026 Updates

    Firebase Scrypt password hash import support is a targeted migration feature — teams on Firebase Auth can now bring existing user credentials into Hanko without forcing a password reset. It fits the pattern of Hanko actively lowering the switching cost from incumbent auth platforms.

  2. 5mo ago

    April 2026 Updates

    Inactivity logouts proactively terminate sessions without user action — a security control commonly required in regulated environments. This continues the session management hardening trend visible across several recent Hanko releases.

  3. 6mo ago

    March 2026 Updates

    Session token transparency improvements give users and developers clearer visibility into active sessions — a small but consistent step toward the kind of audit-friendly session layer that enterprise teams expect from an auth platform.

  4. 7mo ago

    January 2026 Updates

    January 2026 bundles several meaningful improvements across the auth stack: stronger passcode policies, better key management integration, more robust auth flows in Hanko Elements, and expanded localization. No single change is architectural, but the combined scope is a solid incremental release.

  5. 9mo ago

    December 2025 Updates

    OAuth and OIDC third-party integration updates broaden Hanko's compatibility with external identity providers — following the custom OAuth connections feature from September 2025, this keeps the integration surface current.

  6. 9mo ago

    November 2025 Updates

    A smaller release described as fixes and improvements with few specifics in the changelog — consistent with the regular maintenance cadence but below the threshold of user-visible capability additions.