CertiPath.io by CertiPath enables employees and contractors to access enterprise applications and third-party software using strong credentials without the need for passwords. It functions as an authentication gateway that hosts a digital wallet of credentials for the user, allowing the application to set the minimum strength of authentication. CertiPath.io supports virtually all forms of authentication currently available online, making passwords unnecessary. It is compatible with any web application supporting OpenID Connect/OAuth2 and validates strong authenticators like PIV, Derived PIV, PIV-I, CAC, OTP to mobile, and FIDO-2. CertiPath.io leverages TrustMonitor to enhance PKI authentication by continuously monitoring PKI distribution points in any trust fabric. In real time, TrustMonitor verifies the validity and integrity of CAs and the status of Certificate Revocation Lists and Online Certificate Status Protocol responders, safeguarding certificate relationships and ensuring accurate validation information. CertiPath.io meets the authentication gateway requirement and the Zero Trust multi-factor authentication requirement of OMB 22-09, providing step-up and step-down authentication and robust support of PKI-based authentication, including soft-certificates, PIV, PIV-I, or CAC.