Strong authentication
with nothing to carry
Shayype turns a pattern your staff remember into a fresh one-time code at every login. No phone, no token, no app, no hardware to hand in at the gate.
Most MFA assumes there's a phone in a pocket
Authenticator apps, SMS codes and hardware keys all rest on the same assumption: the person logging in has a device with them. In a lot of workplaces that assumption is against the rules.
Phones are locked away at the gate. Personal devices are banned from the floor. Tokens can't be issued to hundreds of shift staff, can't be taken into a sterile area, and get lost or stolen. Staff are left with a username and password, and everyone knows that isn't good enough.
Secure government and defence sites
Wireless and personal electronics prohibited inside controlled areas. Staff still need to reach operational systems.
Prisons and corrections
No devices near people in custody, for anyone. Officers log into offender systems from fixed terminals inside the secure line.
Cleanrooms, GMP and research labs
Gowned-up staff at shared workstations, where phones and USB keys are a contamination risk.
Contact centres
Phones banned at desks to protect card data. Every agent, every shift, every login.
Shared 24/7 workstations
Manufacturing and healthcare shifts where a queue at the terminal is a queue on the line.
Staff without smartphones
Or staff who, reasonably, won't put work apps on a personal phone.
Phones and tokens stay at the gate. Logins don't.Nothing to confiscate, nothing to lose, nothing to steal.
How it works
The secret stays in your head. Only a throwaway code is ever typed.
Choose a pattern once
Pick six or more positions on a small grid: a shape, a letter, a route. It takes under a minute and you never type it anywhere.
Read the code off the grid
At login the grid fills with random digits. Type the digits sitting on your pattern, in order. That's the code.
The code dies after one use
Next login, new digits, new code. Seeing a code tells an onlooker what you typed, not why.
Try it
Runs entirely in your browser. Nothing is sent anywhere.
Powered by Shayype ?
Tap cells in order to build your pattern.
1. Choose your pattern
Tap at least six cells, in the order you'll remember them. Diagonals and gaps make it stronger.
0 of 6 minimum
2. Log in
The grid now shows random digits. Type the digits on your pattern cells, in the same order. They're masked as you type, just as in the real login.
3. Now do it again
That code is finished with. Every login draws new digits, so the code changes every time while your pattern never does.
Straight answers for your security assessor
If you're evaluating this for a restricted environment, these are the questions you'll be asked. Here are the answers as we'd give them to an auditor.
What kind of factor is it?
A knowledge factor: something the user knows. The difference from a password is that the secret itself is never typed, transmitted or stored in usable form. The server holds a split share of it and can confirm a code without being able to reconstruct the pattern. On its own, Shayype is one strong factor. Where your policy requires two independent factors, pair it with something the environment already controls, such as a registered workstation or browser, and you have multi-factor with still nothing for the user to carry.
What if someone watches the login?
On screen, nothing: the code is masked as it's typed, like a password. An observer watching the keyboard, or a keylogger, gets a code that is already dead and that doesn't reveal the pattern; in the demo above you'll see how many patterns a single code fits. Repeated observation of the same user narrows it further, which is why we set a minimum pattern length and encourage diagonals and gaps rather than straight lines. We can share the data behind those complexity rules.
What does the audit trail look like?
Every login attempt is logged with user, terminal, time and outcome. Failed attempts lock out in the normal way. Patterns can be reset by an administrator without anyone ever seeing the old one.
Where this fits, and where it doesn't. Shayype is built for environments that have done a risk assessment and concluded that device-based MFA isn't workable. It's not a fit for payment authentication under PSD2, which requires two independent factor types by law.
Authenticate at the terminal that's already in the room.No app to install, no device to gown up with, no code to wait for.
Common questions
Can we run MFA without phones at all?
Yes. Shayype needs only the screen the user is already logging into. There is no app, no SMS, no token and nothing to issue or collect. For formal two-factor requirements, combine it with a controlled workstation or browser registration.
Does anything need installing on the terminals?
No. The grid is served as part of the login page. It works on shared terminals, thin clients and kiosks, and on any screen a browser can reach.
What happens when someone forgets their pattern?
An administrator resets it and the user chooses a new one, the same way a password reset works today, except nobody can read the old one out to them because nobody can see it.
Does it work with our existing login?
Shayype is ingredient technology: it sits alongside or replaces the password step inside your current authentication flow, and your team integrates and controls it. We'll talk through your identity setup on the first call.
Is it compliant with our framework?
Frameworks such as NIST 800-63, NZISM and Cyber Essentials require MFA in particular contexts and require a documented risk assessment where standard approaches don't fit. We'll help you map Shayype to the specific controls you're assessed against rather than make a blanket claim.
Can a user signal that they're under duress?
Yes, if your integration wants it. Shayype is an ingredient in your login, not a system we run for you, so your team decides what a code means. A second "duress" pattern can log the user in normally while your systems raise a silent alert, restrict what that session can reach, or notify a control room. Prisons, secure sites and lone-worker settings are where this tends to come up.
Is the pattern idea new?
Pattern-based one-time codes have been around since the mid-2000s; our founder invented the original. What's patented in Shayype is the back end: the way the pattern is stored so that a breach of the server doesn't expose anyone's secret.
Tell us about your environment
A 20-minute call. Bring your constraints and your assessor's questions; we'll tell you plainly whether this fits.