System and method linking to accounts using credential-less authentication
A system and method for linking to accounts using credential-less authentication that includes: within a first application context at an account-linking computing service: receiving a request to establish an account link, establishing the account link to a user account of an account service using user credentials, and receiving user identifying information of the first application context and storing the user identifying information in association with the account link; and within a second application context at the account-linking computing service: receiving user identifying information of the second application context, searching and identifying a candidate account link using the user identifying information of the second application context, verifying eligibility for access to the account link, and permitting access to the account link upon successful verification of eligibility.
1 . A method, comprising:
receiving, by one or more devices, a first request to link a first application to an account associated with an external service using first information collected via the first application,
wherein the first information comprises an identifier associated with a user associated with the request and credentials associated with the account,
wherein the first request is associated with a first application context of the first application,
wherein the link between the first application and the account is established based on establishing an account link,
wherein the account link is related to a stored authenticated session, and
wherein the account link is maintained or persistently stored;
receiving, by the one or more devices, a second request to link a second application to the account,
wherein the second request is associated with second information including at least the identifier,
wherein the second request is associated with a second application context related to the second application, and
wherein the second application is different from the first application;
comparing, by the one or more devices, the second information with data stored in a database;
determining, by the one or more devices and based on the comparing, a correspondence between the first information and the second information;
establishing, by the one or more devices and based on the determining, an additional link between the second application and the account based on the second information and without subsequently collecting the credentials,
wherein the maintained or persistently stored account link is utilized in establishing the additional link between the second application and the account, and
wherein establishing the additional link comprises configuring access permissions that set at least one of restrictions or capabilities of the second application when utilizing the established additional link; and
utilizing the established additional link for subsequent transactions associated with the second application context.
2 . The method of claim 1 , wherein the device is associated with an account linking service that provides a simulation of a plurality of applications, that include the first application and the second application, and facilitates interactions between the plurality of applications and one or more external services including the external service.
3 . The method of claim 1 , further comprising:
verifying eligibility for access to the link associated with the first application,
wherein the verification is associated with comparing a first device profile related to the first application and a second device profile related to the second application.
4 . The method of claim 1 , wherein establishing the link associated with the first application and the account comprises configuring access permissions for using the link.
5 . The method of claim 1 , wherein establishing the additional link comprises associating a token with the second application and configuring access permissions for the second application based on one or more parameters.
6 . The method of claim 1 , wherein establishing an account link comprises:
generating a link token;
initiating an authentication module associated with the external service based on communicating the generated link token;
storing account credentials associated with the account link and communicating a public token based on successful authentication from initiating the authentication module; and
transmitting an access token based on receiving a request with the public token.
7 . A device, comprising:
one or more memories; and
one or more processors, coupled to the one or more memories, configured to:
receive a first request to link an account associated with an external service using first information collected via a first application,
wherein the first information comprises an identifier associated with a user associated with the request and credentials associated with the account,
wherein the first request is associated with a first application context of the first application,
wherein the link between the first application and the account is established based on establishing an account link,
wherein the account link is related to a stored authenticated session, and
wherein the account link is maintained or persistently stored;
receive a second request to link a second application to the account,
wherein the second request is associated with second information including at least the identifier, and
wherein the second request is associated with a second application context related to the second application;
compare the second information with data stored in a database;
determine, based on the comparing, a correspondence between the first information and the second information;
establish, based on the determining, an additional link between the second application and the account based on the second information and without collecting the credentials,
wherein the maintained or persistently stored account link is utilized in establishing the additional link between the second application and the account, and
wherein establishing the additional link comprises configuring access permissions that set at least one of restrictions or capabilities of the second application when utilizing the established additional link; and
utilize the established additional link for subsequent transactions associated with the second application context.
8 . The device of claim 7 , wherein the device is associated with an account linking service that provides a simulation of a plurality of applications that include the first application and the second application, and facilitates interactions between the plurality of applications and one or more external services including the external service.
9 . The device of claim 7 , wherein the one or more processors are further configured to:
verify eligibility for access to the link associated with the first application,
wherein the verification is associated with comparing a first device profile related to the first application and a second device profile related to the second application.
10 . The device of claim 7 , wherein establishing the link associated with the first application and the account comprises configuring access permissions for using the link.
11 . The device of claim 7 , wherein the one or more processors are further configured to:
establish, based on the first request to link the first application to the account, a first link linking the first application to the account.
12 . The device of claim 7 , wherein the subsequent collection of the credentials is performed via the additional link established between the second application and the account.
13 . The device of claim 7 , wherein establishing the additional link comprises associating a token with the second application and configuring access permissions for the second application based on one or more parameters.
14 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a device, cause the device to:
receive a first request to link an account associated with an external service using first information collected via a first application,
wherein the first information comprises an identifier associated with a user associated with the request and credentials associated with the account,
wherein the first request is associated with a first application context of the first application,
wherein the link between the first application and the account is established based on establishing an account link,
wherein the account link is related to a stored authenticated session, and
wherein the account link is maintained or persistently stored;
receive a second request to link a second application to the account,
wherein the second request is associated with second information including at least the identifier, and
wherein the second request is associated with a second application context related to the second application;
compare the second information with data stored in a database;
determine, based on the comparing, a correspondence between the first information and the second information;
establish, based on the determining, an additional link between the second application and the account based on the second information and without collecting the credentials,
wherein the maintained or persistently stored account link is utilized in establishing the additional link between the second application and the account, and
wherein establishing the additional link comprises configuring access permissions that set at least one of restrictions or capabilities of the second application when utilizing the established additional link; and
utilize the established additional link for subsequent transactions associated with the second application context.
15 . The non-transitory computer-readable medium of claim 14 , wherein the device is associated with an account linking service that provides a simulation of a plurality of applications that include the first application and the second application, and facilitates interactions between the plurality of applications and one or more external services including the external service.
16 . The non-transitory computer-readable medium of claim 14 , wherein the one or more instructions further cause the device to:
verify eligibility for access to the link associated with the first application,
wherein the verification is associated with comparing a first device profile related to the first application and a second device profile related to the second application.
17 . The non-transitory computer-readable medium of claim 14 , wherein establishing the link associated with the first application and the account comprises configuring access permissions for using the link.
18 . The method of claim 1 , wherein the subsequent collection of the credentials is performed via the additional link established between the second application and the account.
19 . The non-transitory computer-readable medium of claim 14 , wherein the one or more instructions further cause the device to:
establish, based on the first request to link the first application to the account, a first link linking the first application to the account.
20 . The non-transitory computer-readable medium of claim 14 ,
wherein the subsequent collection of the credentials is performed via the additional link established between the second application and the account.