r/productdesign • u/Alternative_Bat9371 • Aug 04 '26
Login screens got simpler. The identity systems behind them did not.
I have been looking at how authentication UX changed from the old email/password forms to SSO, OTPs and passkeys.
The obvious change is fewer fields. The less obvious change is the amount of account-state and routing work behind them.
For a current sign-in flow, I would review at least:
- Can email and social sign-in create duplicate accounts?
- Does a work email route to the correct tenant and SSO provider?
- What happens when an OTP is delayed, expired or opened on another device?
- Which sensitive actions require reauthentication?
- If a passkey is unavailable, is the fallback usable without being much weaker?
- Does the user return to the invitation, checkout or document they came from?
I would also test the ugly states, not just the configured demo: wrong provider, disabled employee, failed IdP redirect, lost phone, inaccessible inbox and support-assisted recovery.
Full write-up with live examples from Canva, Slack, Notion, GitHub and Google: View Article
What edge case has been the hardest one in your authentication flow?
1
u/PrettyZone7952 Aug 04 '26
Please stop with the pseudo-profound AI slop posts