The ToothPic Passkey Provider is a passwordless authentication application designed for Android devices running version 14 and above. It utilizes the unique manufacturing imperfections of a smartphone's camera sensor to generate private cryptographic keys, creating device-bound credentials that are resistant to remote cloning. The solution operates without storing the private key in the device's memory, relying instead on the physical hardware characteristics of the sensor to authenticate users securely.
Built on public key cryptography, the application supports FIDO2 and WebAuthn standards to facilitate phishing-resistant access to online services. Users authenticate via device-native biometrics or PINs, enabling both mobile and cross-device logins through QR code scanning.