No passwords over
the wire. Ever.
Scanning a Miirak QR is not sign-in. The approval you do on your phone is. Here's what happens in the ~2 seconds between the scan and being signed in.
Browser mints a challenge
The website creates a short-lived, single-use code and shows it as a QR. No account details, no token.
You scan with the app
The Miirak app on your (already-authenticated) phone reads the code and fetches the request details.
You see who's asking
The app shows the domain, IP, browser, and time. A phishing site would show the wrong domain here.
Approve with a fingerprint
Only your biometric can complete the approval. The browser is then signed in — the QR becomes unusable.
Not a shared secret
The QR contains no reusable token. Photographing it, forwarding it, or intercepting it in transit is useless without your phone.
Two devices, one approval
The device you're signing in on and the device that authorises the sign-in are different. That kills whole classes of phishing attack.
Sub-2-minute lifetime
Every challenge expires in 90 seconds and is single-use. There is no long-lived link to leak in an email or SMS.
Chained audit trail
Every approval and rejection is recorded with a chained hash so tampering after the fact would be detectable.