Feature
Multi-Factor Authentication
Second-factor and step-up authentication support.
22 providers
117 APIs
15 declared variants
The platform supports or exposes multi-factor authentication — TOTP, SMS, push, passkeys, or hardware keys — including step-up challenges on sensitive operations.
22 API providers on the APIs.io network offer multi-factor authentication. The highest-rated are PropelAuth, Stytch, Soracom, Okta, Amazon Cognito.
Providers
Ranked by API Evangelist rating — Exemplar and Strong are expanded by default.
Strong 8 Solid coverage with minor gaps
PropelAuth
PropelAuth is a B2B SaaS authentication and multi-tenant user management platform purpose-built for organiz...
Stytch
Stytch is an authentication and identity infrastructure provider. Its Consumer and B2B APIs cover passwordl...
Soracom
Soracom is a global IoT cellular connectivity and platform provider headquartered in Tokyo, founded in 2014...
Okta
Okta is the workforce identity incumbent — its Identity Cloud platform (also called the Okta Workforce Iden...
Amazon Cognito
Amazon Cognito is an AWS service that provides authentication, authorization, and user management for web a...
Tray.ai
Tray.ai (formerly Tray.io) is an AI-ready enterprise orchestration platform for data and AI, combining a Me...
emnify
emnify is a cloud-native global IoT cellular connectivity provider operating its own mobile core and SuperN...
WorkOS
WorkOS is the "Enterprise Ready" identity platform for B2B SaaS — providing AuthKit user management, enterp...
Developing 7 Usable, with meaningful gaps to close
Arcadia
Arcadia is a clean-energy access and energy-intelligence company that operates Arc, a utility data platform...
Amazon IAM
Amazon Identity and Access Management (IAM) enables you to manage access to AWS services and resources secu...
Apideck
Apideck is the leading Unified API that doesn't store sensitive customer data. Build and maintain native in...
ThingsBoard
ThingsBoard is an open-source IoT platform for device connectivity, data collection, processing, and visual...
Zitadel
Zitadel is an open source identity infrastructure platform providing secure authentication and user managem...
Microsoft Azure Active Directory
Microsoft Azure Active Directory (Azure AD), now Microsoft Entra ID, is Microsoft's cloud-based identity an...
Login.gov
Login.gov is the U.S. federal government's secure single sign-on and identity verification service for the ...
Thin 5 Limited public surface area
Azure Active Directory
Microsoft's cloud-based identity and access management service that helps employees sign in and access reso...
Casdoor
Casdoor is an open-source, AI-first identity and access management (IAM) and MCP gateway authentication ser...
Descope
Descope is a customer and agentic identity access management (CIAM) platform founded in 2022 by veterans of...
Zero Trust Architecture
Zero Trust Architecture (ZTA) is a security framework defined by NIST SP 800-207 that requires all users an...
Authelia
Authelia is an open source authentication and authorization server providing multi-factor authentication an...
What Providers Actually Declared
This feature is a canonical term. These are the free-text strings
providers wrote in their own apis.yml that map onto it.
AAL2 with TOTP, SMS/voice, push, security keys, PIV/CAC, and platform passkeysAdaptive Multi-Factor AuthenticationArcadia Connect hosted credential UI handles utility logins, MFA, and one-time passcodes without partners storing utility credentialsConsumer Authentication API (Magic Links, OTP, OAuth, Passwords, TOTP, WebAuthn / Passkeys, Crypto Wallets, Sessions, Users)Core Essentials at $14/user/mo: Adaptive MFA, Privileged Access, Lifecycle Mgmt, Access GovernanceDrag-and-drop Descope Flows for designing authentication, signup, MFA, step-up, and account-recovery journeys with no codeFIDO2 / PasskeysJWT and API-key (4.3+) authentication, OAuth2 federation, two-factor authMulti-Factor AuthenticationMulti-factor authenticationMulti-factor authentication (TOTP) enforceable per organizationMulti-factor authentication with trusted device fingerprinting (90-day skip window)Sealed sessions, magic auth, passkeys, social, password, enterprise SSOSoracom Access Management (SAM) — sub-users, roles, IAM-style policy documents, MFAWebAuthn / Passkeys
Scroll for all 15