ProductsAuthorizationAuditing

Introducing Multifactor Lite: Share Online Accounts by Sending a Link

In our second Lock-In Week we cut Multifactor down to the one thing we care about most: sharing an online account by sending a link, with permissions you choose, a live log of every action, and instant revocation. Try it today.

6 min read

On this page

In July 2025 I wrote that, when it comes to sharing an account, a password manager is “nothing more than a glorified encrypted email,” and that we were building Checkpoint to do better. Over the following year we kept building around that idea: a vault, autofill, a browser extension, desktop and mobile apps, payment cards, password imports and an AI assistant. By September, sharing (the reason we started) sat four levels deep in a settings menu.

So in our second Lock-In Week we took almost all of it out. What was left is Multifactor Lite, a small app that does one thing: share an online account by sending a link. You choose what each link can do, you watch what happens through it as it happens, and you can take it back in one click. You can try it today.

One thing, done well

There are excellent password managers already. The autofill team at one of the big ones is larger than our whole company, and we were never going to out-build them on autofill. Meanwhile, the part of the product nobody else does well kept getting buried under the parts everybody does.

Midway through the week I put it to the team plainly. Our app “was trying to do too much and it was good at nothing, was mediocre at everything.” The goal was to be fantastic at the one thing we wanted to do, and we wrote that down as the first rule for everything we built.

That also settled what Lite is for. It doesn't replace your password manager. Keep the one you use. Lite is the easy way to share the accounts in it with the people you work with.

Lock-In Week 2

In August we ran our first Lock-In Week: four days, five engineers, one room, and a fresh research repository where everything merged without review. It told us we could build the pieces. Lock-In Week 2, from September 21 to 25, asked whether we could ship them.

We changed the rules to match that question:

  • Everything landed in our production repository, with continuous integration and code review left on. About 70 pull requests merged that week.
  • We worked against a real website from the first morning, instead of test sites we had written ourselves. The first Lock-In taught us that our own fixtures hid the bugs that mattered.
  • Instead of five separate tracks, the team worked on one product flow end to end, each person owning a part of it: Pierre on the automation that signs in for you, Dave on enforcing what each link may do, James on the design of the app, Jayani on adding accounts, and me on the service that serves a shared session to the person you share it with.
  • The week counted as a success only if one real site worked end to end, in production.

We wrote the target demo down on Monday morning. I add my account and send a link to Dave, who is straight in. I ask him to do something his link forbids, and it's blocked. Then I open History and read exactly what he did.

We chose Hacker News as that first site. It has a real sign-in and real actions: voting, favoriting, hiding and posting. The last piece of the end-to-end flow merged at 11:03 pm on Friday, with 57 minutes to spare. We spent the following week polishing and hardening it, and that is what you can use today.

Introducing Multifactor Lite

Lite is a single page. Each account you add is a card, and each card has two tabs: Share and History. The rest of this post walks through it, one short clip at a time.

Connect an account once

Pick the site and sign in once with the account's username and password. Multifactor then signs in to the site itself, in a secure browser in the cloud, and keeps that session signed in, checking it every hour. From then on you can open the account straight from Multifactor without typing its password, and it's ready to share.

Open Share, name the link after the person or team it's for, choose what it can do, and create it. You get two things to send: a link and its pass. Your teammate opens the link, enters the pass, and lands on the site already signed in. They never see your password, and they don't need a Multifactor account. If they do have one, the account appears under “Shared with me” on their dashboard, and their name appears in your History.

Every link has its own permissions: Read only, Read and write, or Full access, each described in plain words for that site. You can give your marketing team read only access and one colleague read and write access to the same account, with different links. On a read only link to Hacker News, the voting arrows are greyed out, and a vote is refused before it ever reaches Hacker News.

See every action, live

History shows who used which link and what they did with it. While someone is using a link, their visit is marked Live and its count of actions goes up as they work. Open the visit and you see each step in plain language, including anything the link blocked.

Revoke access instantly

When someone no longer needs access, revoke their link. Their open tab switches to “Your access to this account was removed”, in under a second in our tests, and every other link keeps working. There is no password to change and nothing to chase. To cut off everyone at once, archive the account; restoring it brings back the same links.

How it works

When you connect an account, Multifactor signs in once, in an isolated browser on our servers. That signed-in session is what every link uses. There is one session per account however many links you create, so the site sees one person rather than a crowd signing in from everywhere.

Your teammate reaches the site through our proxy, on a separate domain made for shared sessions. The account's password never reaches their browser. Each link's permissions are a policy checked on every request they make, and every request is written to a plain-language log. Those are the same policy and logging layers we first wrote about for sharing with AI agents, and the log is what you read in History.

What we cut

Lite has no vault, no autofill, no browser extension, no desktop or mobile app, no cards or addresses, no password imports and no AI assistant. Each of those took time away from sharing, and every one of them is something your current password manager already does. Removing them is what made it possible to finish the part that only we do.

What it doesn't do yet

  • Hacker News is the only site today. We picked one site and made it work end to end before adding more. LinkedIn is next, followed by sites that need passkeys, two-factor codes, or sign-in with Google.
  • It's new, and now and then a shared session gets signed out. Multifactor notices, signs back in on its own, and pauses that account's links until it has. We spent most of this week making that rarer.
  • Sharing with AI agents already works through the same links, and it gets its own post soon.

What's next

In October our goal is to go from one site to dozens. Every site we add gets automated checks that lock it in once it works, so a site that works today keeps working. As I put it at the end of the week, “It can only get better. It can never regress.”

Try it

Sign up at lite.multifactor.com, connect your Hacker News account, and send a link to a friend. Give them read only access, watch their visit appear in History, and then revoke it. It takes about two minutes, and we would love to hear what you think.

We're redefining zero-trust — so you can protect your accounts with confidence.

Identity is your first and last line of defense, and the root cause of most application security breaches. Multifactor's provably secure zero-trust solutions cryptographically guarantee that only authorized users can access sensitive data, turning identity into your greatest asset in the fight against cyber threats. Learn more about our research, or reach out to explore working together.

Related Posts

Mapping the actions behind Amazon’s website

Mapping the actions behind Amazon’s website

2026-09-17

How we approached coverage, request classification, and parallel exploration while building a map of Amazon’s user actions.

How to Share an Account With Your Agent and Know What It Did

How to Share an Account With Your Agent and Know What It Did

2026-09-15

Checkpoint gives your agent scoped access to any online account, enforced at the network layer inside a trusted execution environment, with a verifiable log of every action it took.

Introducing Checkpoint: A Better Way to Share Online Accounts

Introducing Checkpoint: A Better Way to Share Online Accounts

2025-07-07

Checkpoint uses novel cryptographic techniques to enable easy revocable, non-repudiable, and fine-grained sharing of any online account resource.