We are rolling out Oneway™ gradually, and it may not yet be available to you.
Oneway™ is Ackaia ID's certificate-based sign-in option. It lets an eligible user authenticate to Ackaia ID using a client TLS certificate installed in a supported browser, without entering an email address or account password during the Oneway™ sign-in itself.
Oneway™ uses mutual TLS (mTLS). In addition to your browser verifying Ackaia's TLS identity, Ackaia verifies a client certificate that represents your Ackaia ID.
Oneway™ is available only to accounts where the feature has been enabled.
To activate Oneway™, you must be able to authenticate normally to your Ackaia ID.
Activation and certificate issuance require:
your current Ackaia ID password; and
multifactor authentication if MFA is enabled on your account.
You will also need to create a password for the certificate package. This password must contain at least 16 characters.
The certificate password protects the downloadable certificate package. It is separate from your Ackaia ID password.
When Oneway™ is available for your account:
Sign in to Ackaia ID using your normal sign-in method.
Open the Security area of your account.
Find the Oneway™ section. When available, this is what you should see:

Start the activation process.
Confirm your Ackaia ID password.
Complete MFA if it is enabled on the account.
Create a certificate password containing at least 16 characters.
Issue the Oneway™ certificate.
Download the certificate package when it becomes available.
The downloaded credential is provided as a password-protected .p12 certificate package.
Download and protect the certificate when it is issued. Ackaia does not retain your private key for later recovery
After downloading the certificate package, import it into the browser or operating-system certificate store used by that browser.
During import, your browser or operating system may ask for the certificate password you created when Oneway™ was issued.
The exact import procedure depends on your browser and operating system. In general, you should:
open the browser or operating-system certificate settings;
choose the option for importing a personal/client certificate;
select the downloaded .p12 file;
enter the certificate password;
complete the import;
return to Ackaia ID and enable Oneway™ for that browser when the option becomes available.
Once the certificate is installed and Oneway™ is enabled for the browser, that browser can use the certificate for Oneway™ authentication.
When Oneway™ is available and a valid Oneway™ certificate is installed, the Ackaia ID sign-in page can present the Login With Oneway™ option.
To sign in:
open the Ackaia ID sign-in page;
select Login With Oneway™;
if your browser asks you to choose a client certificate, select your Ackaia Oneway™ certificate;
allow the browser to continue with the certificate-based authentication.
Ackaia then validates the certificate through the dedicated Oneway™ mutual-TLS sign-in service. If the certificate is valid and the account is permitted to sign in, Ackaia ID establishes the authenticated session.
You do not need to enter your email address or Ackaia ID password during this Oneway™ sign-in flow.
Your Oneway™ certificate is an authentication credential representing your Ackaia ID.
Anyone who obtains a usable copy of the certificate together with access to its private key may be able to attempt authentication as the identity represented by that certificate.
Treat the certificate with the same care you would give another high-value authentication credential:
do not share the .p12 file;
do not send it by email or ordinary support channels;
do not disclose its certificate password;
avoid installing it on devices you do not control;
remove or revoke it if the device or browser is no longer trusted.
Oneway™ client certificates are issued with a limited lifetime. The current certificate validity period is 90 days.
After the certificate expires, it can no longer be used for Oneway™ authentication. You will need to issue or renew a valid Oneway™ certificate through the Ackaia ID Security area.
Using a limited certificate lifetime reduces the amount of time an old credential can remain useful if it is no longer actively managed.
Oneway Basic is included at no cost and allows you to issue and manage the lifecycle of one active certificate at a time.
Oneway Plus, available for USD 1.99/month, is designed for users who want to use Oneway™ across multiple devices and need more control over their credentials.
Plus allows multiple active certificates, advanced certificate management, custom certificate names, configurable expiration periods within Ackaia's security limits, detailed lifecycle history for events such as issuance, renewal, and revocation, and simplified certificate renewal.
With simplified renewal, you can generate the replacement credential from Ackaia ID with a single renewal action instead of manually revoking the expiring certificate and configuring a new one from scratch. For security reasons, the renewed certificate must still be downloaded and installed in your browser or device by you.
Oneway™ Basic includes the essential certificate-based sign-in experience at no cost, while Oneway™ Plus adds multi-device support and more advanced certificate-management features.
Feature | Oneway™ Basic | Oneway™ Plus |
|---|---|---|
Price | Free | USD 1.99/month |
Simultaneous active certificates | 1 certificate | Up to 5 certificates |
Use across multiple devices | Limited to one active certificate at a time | Supported |
Certificate lifecycle management | Standard | Advanced |
Custom certificate names | Not available | Available |
Custom expiration period | Standard certificate lifetime | Configurable within Ackaia's security limits |
Certificate renewal | Standard replacement process | Simplified renewal |
Detailed lifecycle history | Not available | Issuance, renewal, revocation, and other certificate events |
Passwordless Oneway™ sign-in | Included | Included |
Note: Simplified renewal does not install the renewed certificate automatically. For security reasons, you must still download and install the new certificate in the appropriate browser or device
When your certificate is approaching expiration, the renewal process depends on your Oneway™ plan. Oneway Basic users can replace the expiring credential through the standard certificate lifecycle controls, while Oneway Plus provides a simplified renewal workflow.
A renewed or replacement certificate must be downloaded and installed in the browser in the same way as the original certificate.
Do not assume that replacing the file on disk automatically updates the certificate already imported into your browser.
If you lose control of the device, browser profile, certificate package, or another environment containing your Oneway™ credential, revoke the certificate from Ackaia ID as soon as possible.
Revocation tells Ackaia not to accept that certificate for future Oneway™ authentication even if its original 90-day validity period has not ended.
After revocation, remove the old certificate from affected browsers or devices and issue a replacement only from a trusted environment.
If the certificate is removed from the browser or operating-system certificate store, that browser can no longer use that credential for Oneway™ sign-in.
This does not delete your Ackaia ID. You can still use another sign-in method available to your account and, if permitted, issue or install another Oneway™ certificate.
The certificate password protects the exported .p12 package.
Ackaia does not retain the private key or a recoverable copy of the certificate package for you. If you can no longer import or use the package because the required password is unavailable, use your normal Ackaia ID authentication to issue a replacement credential where permitted.
The standard Ackaia ID website does not continuously request a client certificate from every visitor.
Certificate authentication is performed only when the user deliberately chooses Login With Oneway™. The browser is then directed through Ackaia's dedicated Oneway™ mutual-TLS authentication service.
This keeps normal Ackaia ID browsing and standard sign-in separate from certificate authentication.
Oneway™ provides another way to prove possession of an authentication credential. It does not remove the other security controls that protect Ackaia ID.
Ackaia can still apply account-security, risk, suspension, session, or policy checks before allowing a session to be established.
A valid client certificate should therefore not be understood as an unconditional guarantee that a sign-in will always be accepted.
Check the following:
Oneway™ is currently available for your account;
you completed Oneway™ activation;
the correct certificate is installed in the browser or certificate store used by that browser;
the certificate has not expired;
the certificate has not been revoked;
you are using the browser profile where the certificate was installed.
If the problem continues, sign in using another available Ackaia ID method and review the Oneway™ status in your account Security area.
A browser can contain more than one client certificate. When this happens, it may ask you which identity certificate should be presented to Ackaia.
Select the Ackaia Oneway™ certificate associated with the Ackaia ID you intend to access.
If you are unsure which certificate is correct, cancel the certificate selection rather than presenting an unrelated credential.
Installing Oneway™ in one browser does not automatically make the certificate available in every browser or device.
A new browser or device must have an appropriate valid Oneway™ credential available before it can use certificate-based sign-in.
Only install Oneway™ credentials on devices and browser profiles you trust.
If you cannot activate, issue, install, renew, revoke, or use Oneway™, contact Ackaia Support:
https://support.ackaia.com/hc/tickets/new
When reporting a problem, include:
the step where the problem occurs;
your browser and operating-system type;
the error message shown by Ackaia ID, if any;
whether the certificate has already been issued and installed;
whether Oneway™ previously worked in that browser.
Never attach the .p12 certificate, its private key, its password, your Ackaia ID password, or an MFA code to a support case.
Oneway™ turns possession of a valid client certificate into a fast Ackaia ID sign-in method. Protect that certificate carefully, revoke it when trust is lost, and keep another account-recovery or sign-in method available