Using Oneway™ for Passwordless Sign-In

We are rolling out Oneway™ gradually, and it may not yet be available to you.

Oneway™ is Ackaia ID's certificate-based sign-in option. It lets an eligible user authenticate to Ackaia ID using a client TLS certificate installed in a supported browser, without entering an email address or account password during the Oneway™ sign-in itself.

Oneway™ uses mutual TLS (mTLS). In addition to your browser verifying Ackaia's TLS identity, Ackaia verifies a client certificate that represents your Ackaia ID.

Oneway™ is available only to accounts where the feature has been enabled.

Before you activate Oneway™

To activate Oneway™, you must be able to authenticate normally to your Ackaia ID.

Activation and certificate issuance require:

You will also need to create a password for the certificate package. This password must contain at least 16 characters.

The certificate password protects the downloadable certificate package. It is separate from your Ackaia ID password.

Activate Oneway™ and issue your certificate

When Oneway™ is available for your account:

  1. Sign in to Ackaia ID using your normal sign-in method.

  2. Open the Security area of your account.

  3. Find the Oneway™ section. When available, this is what you should see:

  4. Start the activation process.

  5. Confirm your Ackaia ID password.

  6. Complete MFA if it is enabled on the account.

  7. Create a certificate password containing at least 16 characters.

  8. Issue the Oneway™ certificate.

  9. Download the certificate package when it becomes available.

The downloaded credential is provided as a password-protected .p12 certificate package.

Download and protect the certificate when it is issued. Ackaia does not retain your private key for later recovery

Install the certificate in your browser

After downloading the certificate package, import it into the browser or operating-system certificate store used by that browser.

During import, your browser or operating system may ask for the certificate password you created when Oneway™ was issued.

The exact import procedure depends on your browser and operating system. In general, you should:

  1. open the browser or operating-system certificate settings;

  2. choose the option for importing a personal/client certificate;

  3. select the downloaded .p12 file;

  4. enter the certificate password;

  5. complete the import;

  6. return to Ackaia ID and enable Oneway™ for that browser when the option becomes available.

Once the certificate is installed and Oneway™ is enabled for the browser, that browser can use the certificate for Oneway™ authentication.

Sign in with Oneway™

When Oneway™ is available and a valid Oneway™ certificate is installed, the Ackaia ID sign-in page can present the Login With Oneway™ option.

To sign in:

  1. open the Ackaia ID sign-in page;

  2. select Login With Oneway™;

  3. if your browser asks you to choose a client certificate, select your Ackaia Oneway™ certificate;

  4. allow the browser to continue with the certificate-based authentication.

Ackaia then validates the certificate through the dedicated Oneway™ mutual-TLS sign-in service. If the certificate is valid and the account is permitted to sign in, Ackaia ID establishes the authenticated session.

You do not need to enter your email address or Ackaia ID password during this Oneway™ sign-in flow.

What the certificate represents

Your Oneway™ certificate is an authentication credential representing your Ackaia ID.

Anyone who obtains a usable copy of the certificate together with access to its private key may be able to attempt authentication as the identity represented by that certificate.

Treat the certificate with the same care you would give another high-value authentication credential:

Oneway™ certificate validity

Oneway™ client certificates are issued with a limited lifetime. The current certificate validity period is 90 days.

After the certificate expires, it can no longer be used for Oneway™ authentication. You will need to issue or renew a valid Oneway™ certificate through the Ackaia ID Security area.

Using a limited certificate lifetime reduces the amount of time an old credential can remain useful if it is no longer actively managed.

Oneway™ Plans

Oneway Basic is included at no cost and allows you to issue and manage the lifecycle of one active certificate at a time.

Oneway Plus, available for USD 1.99/month, is designed for users who want to use Oneway™ across multiple devices and need more control over their credentials.

Plus allows multiple active certificates, advanced certificate management, custom certificate names, configurable expiration periods within Ackaia's security limits, detailed lifecycle history for events such as issuance, renewal, and revocation, and simplified certificate renewal.

With simplified renewal, you can generate the replacement credential from Ackaia ID with a single renewal action instead of manually revoking the expiring certificate and configuring a new one from scratch. For security reasons, the renewed certificate must still be downloaded and installed in your browser or device by you.

Compare Oneway™ plans

Oneway™ Basic includes the essential certificate-based sign-in experience at no cost, while Oneway™ Plus adds multi-device support and more advanced certificate-management features.

Feature

Oneway™ Basic

Oneway™ Plus

Price

Free

USD 1.99/month

Simultaneous active certificates

1 certificate

Up to 5 certificates

Use across multiple devices

Limited to one active certificate at a time

Supported

Certificate lifecycle management

Standard

Advanced

Custom certificate names

Not available

Available

Custom expiration period

Standard certificate lifetime

Configurable within Ackaia's security limits

Certificate renewal

Standard replacement process

Simplified renewal

Detailed lifecycle history

Not available

Issuance, renewal, revocation, and other certificate events

Passwordless Oneway™ sign-in

Included

Included

Note: Simplified renewal does not install the renewed certificate automatically. For security reasons, you must still download and install the new certificate in the appropriate browser or device

Renewing your Oneway™ certificate

When your certificate is approaching expiration, the renewal process depends on your Oneway™ plan. Oneway Basic users can replace the expiring credential through the standard certificate lifecycle controls, while Oneway Plus provides a simplified renewal workflow.

A renewed or replacement certificate must be downloaded and installed in the browser in the same way as the original certificate.

Do not assume that replacing the file on disk automatically updates the certificate already imported into your browser.

Revoke Oneway™ if the certificate may be compromised

If you lose control of the device, browser profile, certificate package, or another environment containing your Oneway™ credential, revoke the certificate from Ackaia ID as soon as possible.

Revocation tells Ackaia not to accept that certificate for future Oneway™ authentication even if its original 90-day validity period has not ended.

After revocation, remove the old certificate from affected browsers or devices and issue a replacement only from a trusted environment.

What happens if I delete the certificate?

If the certificate is removed from the browser or operating-system certificate store, that browser can no longer use that credential for Oneway™ sign-in.

This does not delete your Ackaia ID. You can still use another sign-in method available to your account and, if permitted, issue or install another Oneway™ certificate.

What happens if I forget the certificate password?

The certificate password protects the exported .p12 package.

Ackaia does not retain the private key or a recoverable copy of the certificate package for you. If you can no longer import or use the package because the required password is unavailable, use your normal Ackaia ID authentication to issue a replacement credential where permitted.

Why Oneway™ uses a separate sign-in service

The standard Ackaia ID website does not continuously request a client certificate from every visitor.

Certificate authentication is performed only when the user deliberately chooses Login With Oneway™. The browser is then directed through Ackaia's dedicated Oneway™ mutual-TLS authentication service.

This keeps normal Ackaia ID browsing and standard sign-in separate from certificate authentication.

Oneway™ does not replace account security

Oneway™ provides another way to prove possession of an authentication credential. It does not remove the other security controls that protect Ackaia ID.

Ackaia can still apply account-security, risk, suspension, session, or policy checks before allowing a session to be established.

A valid client certificate should therefore not be understood as an unconditional guarantee that a sign-in will always be accepted.

If Login With Oneway™ does not appear

Check the following:

If the problem continues, sign in using another available Ackaia ID method and review the Oneway™ status in your account Security area.

If the browser asks which certificate to use

A browser can contain more than one client certificate. When this happens, it may ask you which identity certificate should be presented to Ackaia.

Select the Ackaia Oneway™ certificate associated with the Ackaia ID you intend to access.

If you are unsure which certificate is correct, cancel the certificate selection rather than presenting an unrelated credential.

If you change browsers or devices

Installing Oneway™ in one browser does not automatically make the certificate available in every browser or device.

A new browser or device must have an appropriate valid Oneway™ credential available before it can use certificate-based sign-in.

Only install Oneway™ credentials on devices and browser profiles you trust.

Need help?

If you cannot activate, issue, install, renew, revoke, or use Oneway™, contact Ackaia Support:

https://support.ackaia.com/hc/tickets/new

When reporting a problem, include:

Never attach the .p12 certificate, its private key, its password, your Ackaia ID password, or an MFA code to a support case.

Oneway™ turns possession of a valid client certificate into a fast Ackaia ID sign-in method. Protect that certificate carefully, revoke it when trust is lost, and keep another account-recovery or sign-in method available