Approve what matters, with a touch.
Require a passkey to cryptographically sign each high-value action — and email the receipt instantly. Strong customer authentication, built in.
Per-action approval
Every payment is signed by the user's passkey — not a stored token. Replay-proof and non-repudiable.
What you sign is what you see
Amount, recipient, and currency are bound into the signature, so they can't be altered after approval.
Instant receipts
Paswad emails a signed receipt the moment a transaction is approved — your real-time tripwire.
Add signing to your app
For developers ›Transaction signing — common questions
How per-transaction passkey signing stops fraud and meets SCA.
How does transaction signing stop payment fraud?
Every high-value action is cryptographically signed by the user's passkey at the moment of approval — not authorised by a stored token or session. A stolen session or replayed request cannot move money, because there is no fresh, valid signature for it.
The amount, recipient, and currency are bound into the signature, so an attacker cannot alter the details after you approve. Learn how passkeys work.
Does transaction signing meet PSD2 strong customer authentication (SCA)?
Yes. A passkey tap combines possession (the device holding the private key) with inherence (your biometric), satisfying the two-factor requirement for strong customer authentication under PSD2.
Because the signature is bound to the specific payment, it also meets the dynamic linking requirement that the authentication code be tied to the exact amount and payee. See our compliance posture.
What exactly gets signed in a transaction?
What you sign is what you see. The amount, recipient, and currency shown in the approval prompt are bound directly into the cryptographic signature, so they cannot be changed after you approve them.
Paswad emails a signed receipt the instant a transaction is approved, giving you a real-time tripwire for anything you did not authorise.
How does signing prevent disputes and repudiation?
Each approval produces a non-repudiable, replay-proof signature that only the account holder's passkey could have created. That gives you cryptographic proof of who approved a specific payment and exactly what they approved — far stronger evidence than a password or SMS code.
Paswad is the identity and signing layer and never holds funds; your payment provider settles the money while the signature stands as the audit record. See the verified identity behind every signature.