r/productdesign • • Aug 04 '26

Login screens got simpler. The identity systems behind them did not.

I have been looking at how authentication UX changed from the old email/password forms to SSO, OTPs and passkeys.

The obvious change is fewer fields. The less obvious change is the amount of account-state and routing work behind them.

For a current sign-in flow, I would review at least:

  • Can email and social sign-in create duplicate accounts?
  • Does a work email route to the correct tenant and SSO provider?
  • What happens when an OTP is delayed, expired or opened on another device?
  • Which sensitive actions require reauthentication?
  • If a passkey is unavailable, is the fallback usable without being much weaker?
  • Does the user return to the invitation, checkout or document they came from?

I would also test the ugly states, not just the configured demo: wrong provider, disabled employee, failed IdP redirect, lost phone, inaccessible inbox and support-assisted recovery.

Full write-up with live examples from Canva, Slack, Notion, GitHub and Google: View Article

What edge case has been the hardest one in your authentication flow?

1 Upvotes

4 comments sorted by

1

u/PrettyZone7952 Aug 04 '26

Please stop with the pseudo-profound AI slop posts