BeardPowered ยท Auth ยท Sovereign

Approve logins
from your phone.
No Authy. No Google.

BeardAuth is a GitHub Mobile-style push notification approval system for every BeardPowered app -- and a sovereign TOTP authenticator that keeps your 2FA seed secrets on your server, not Authy's. Authy got breached in 2024. Google Authenticator syncs to Google cloud. BeardAuth keeps it yours.

auth.beard.energy
LIVE
๐Ÿ””
Login request -- Scout from Chrome
APPROVE?
โœ“
Approved -- JWT issued 4hr session
DONE
๐Ÿ”
TOTP: 847 293 -- 28 seconds remaining
ACTIVE
๐Ÿ›ก๏ธ
2FA seeds stored on your VPS -- not Authy
SECURE
0
Seed secrets on corporate servers
K1
Push approval for every login
TOTP
RFC 6238 compliant
$0
Per-user auth fees
What It Does

Your seeds.
Your server.

2FA seed secrets are the keys to every account you protect. Authy stores them on their servers. Google syncs them to Google. BeardAuth stores them on your VPS -- air-gapped from every corporate cloud.

TOTP
RFC 6238 compliant codes generated locally
Standard TOTP codes -- compatible with any service that accepts Google Authenticator. Generated locally from seeds on your server. Nobody else has them.
Push Approval
GitHub Mobile-style login approval
Any BeardPowered app can redirect to BeardAuth for login. Your phone gets a push notification. Tap approve. The app gets a session token. No password typed on the app.
Crew Management
One auth server for your whole crew
All users managed in BeardAuth. Each user gets their own credentials. You control who has access to what, from one screen.
JWT Sessions
4-hour sessions across the suite
One BeardAuth approval gives you a JWT that works across your BeardPowered apps for 4 hours. One login. Whole suite.
What It Replaces

Stop paying forever
for tools you'll never own.

Every one of these charges you monthly. None of them talk to each other. All of them own your data.

Competitor
Authy
Free (breached 2024)
76 million phone numbers exposed in 2024 breach
Your seed secrets on Authy servers
Closed source -- cannot verify security
Single point of failure for all your 2FA
BeardPowered
BeardAuth
Yours. Forever.
Seed secrets on your VPS -- not Authy
Push notification approval for suite logins
Open architecture -- you can audit every line
One auth server for your whole crew
Competitor
Google Authenticator
Free (syncs to Google)
Seeds synced to Google cloud by default
Google has access to your 2FA seeds
No push approval for app logins
Account compromise means all 2FA compromised
How It Connects

One login.
Whole suite.

BeardAuth is the authentication layer for every BeardPowered app.

Every BeardPowered app can redirect to BeardAuth for login instead of its own auth
Field and Scout are the first two pilot apps for BeardAuth push approval
Contacts user records sync with BeardAuth crew management
Scout can surface BeardAuth login activity and flag unusual access patterns
Get Started

Your 2FA seeds.
Your server.

Sovereign TOTP authenticator with push notification approval for your entire BeardPowered stack.

Open BeardAuth Talk to Michael Back to Suite