ID.me authenticator for desktop: signing in from a Mac window

The search usually starts at the worst possible moment. A government service is open in a browser tab, the password went through, and the next screen asks for a code that lives on a phone in another room. Anyone who does this twice a week starts looking for an ID.me authenticator for desktop, on the assumption that a Mac application must exist somewhere. It does not, and that turns out to be less of a problem than it sounds, because the phone is not the only way past that screen.

What ID.me actually publishes for a computer

The ID.me Authenticator app has exactly two distribution channels, and ID.me's own help documentation names them both.

There are two ways to download the ID.me Authenticator app: For iOS devices (iPhone, iPad, Apple Watch), visit the App Store. For Android devices, visit Google Play. Source: help.id.me

The App Store listing matches that exactly. ID.me Authenticator is published by ID.me, Inc., it is free, it sits in the Productivity category at 23.3 MB, and the compatibility line reads "Requires iOS 12.0 or later." The device list above the description reads iPhone, iPad, Apple Watch. There is no fourth entry.

That missing fourth entry is the whole answer. When a developer allows an iPhone and iPad build to be installed on Apple silicon, Apple adds a Mac line to the listing and names the minimum macOS version. ID.me has not done that. Searching the Mac App Store for ID.me returns third party authenticator apps from unrelated developers, not anything published by ID.me, Inc.

So the literal request cannot be satisfied. There is no ID.me Authenticator on a Mac, by any install route, including the emulator pages that rank for this query and are written for Windows machines running Android in a virtual environment.

What a Mac does have is a browser, and the thing being signed into is a website. The ID.me Wallet, the sign-in prompt, the MFA challenge and the consent screen that shares verified details with an agency are all web pages. The realistic version of this search is therefore not "where is the Mac app" but "which MFA method can a Mac complete without reaching for a phone, and how does the sign-in page stop being a tab that keeps breaking."

The six MFA methods, and which ones need a phone

ID.me publishes a list of MFA methods with a security rating attached to each one. Four are listed as common methods and two more require hardware.

Method ID.me's rating Needs a phone in hand
Passkey Very strong No
Security Key (USB) Very strong No
Code Generator Strong Yes, the Authenticator app
NFC-Enabled Security Key Very strong Yes, plus a YubiKey 5 NFC
Push Notification Moderately secure Yes, the Authenticator app
Text message or phone call Fairly secure Yes

Read down the right hand column and the shape of the problem changes. Two of the six methods rated "very strong" by ID.me itself never touch a phone at all. Passkey uses the unlock method already built into the machine doing the signing in, and a USB security key is tapped on the desk.

ID.me's guidance on how many methods to keep is explicit, and it is worth following before changing anything.

Tip: To enable MFA, choose one of the options below and follow the setup link for that method. Source: help.id.me

The same page states a recommendation of at least two MFA methods so that losing access to one does not lock the account. Backup codes are a separate stand-alone method: ID.me issues 12 one-time codes, numbered so it is clear which have been spent, and after the last one is used a fresh set of 12 arrives with the next block of numbers.

There is also a documented position on text messages. ID.me's own explainer on how MFA protects a wallet notes that SMS has fallen out of favour because of SIM swapping and interception, and points readers towards app-based and hardware methods instead. That is a rare thing to find in a vendor's help centre, and it is a useful signal about which method to pick.

Passkey is the method that removes the phone

Passkey is the only method on that list where the Mac in front of the reader is both the thing signing in and the thing proving identity.

Passkey is a secure multi-factor authentication (MFA) method that helps protect your ID.me Wallet. You can sign in using your fingerprint, Face ID, or device PIN. Source: help.id.me

The setup path for a computer is short. Select Passkey, choose Continue in the pop-up, complete the machine's own unlock step, then rename the device inside the wallet so a laptop and a desktop can be told apart later. ID.me's documentation is clear that a passkey can be registered on more than one device, that each device is set up separately, and that each one can only be linked to a single wallet.

Two warnings on that page matter more than the steps. The first is about browsers: ID.me recommends the latest version of Google Chrome for passkey and notes that switching browsers between setup and sign-in can cause failures. The second follows from the first. If the passkey was registered in one browser, the sign-in has to happen in that same browser, which makes the choice of where the ID.me page lives a practical decision rather than a matter of taste.

This is the point where a dedicated window earns its place. A window pinned to one site, using one browser engine, with one stored set of credentials, removes the whole class of failure where a passkey was created in one place and offered in another.

The hardware alternative

A USB security key carries the same "very strong" rating and has no browser preference attached to it. It is tapped, the sign-in completes, and nothing depends on which machine registered it. For anyone who signs in from several computers, that is the more portable answer, and it costs the price of the key.

Why the sign-in keeps breaking in a browser

ID.me maintains separate help articles for browser failures, which is a good indication of how often they happen. One covers the general case.

If you're having trouble verifying your identity, your web browser may need to be updated or cleared of temporary files. Source: help.id.me

Another covers a specific error message, and its first two suggestions are telling.

You may see "We couldn't verify your browser" if your browser blocks a required security check or if JavaScript is turned off. Source: help.id.me

The fixes listed are to try a different browser, try a different device, and confirm JavaScript is on. Read that as a description of the environment ID.me needs: a current browser engine, JavaScript enabled, and nothing in the way of a security check. A main browser with a long-lived profile, a stack of privacy extensions and years of accumulated site data is the opposite of that environment, and it is where most people attempt this.

Then there is the tab problem. ID.me publishes a whole article on returning to the right tab mid-verification, because document upload and the video selfie step often move to a phone and then hand control back to the computer.

Keep ID.me open on your computer. When prompted, enter your phone number. We'll send you a text message. Keep this browser tab open. Source: help.id.me

"Keep this browser tab open" is an instruction that fails constantly in a browser holding thirty tabs, where Cmd+W is muscle memory and the frontmost tab is often not the intended one. A window that contains one site and nothing else cannot lose that tab, because there is nothing else in it to close by mistake.

Giving the ID.me sign-in a window of its own

macOS has a documented route for this that costs nothing, and Apple is precise about what the result is.

A web app functions independently of Safari. It shares no browsing history, cookies, website data, or settings with Safari. Source: support.apple.com

In Safari the path is File then Add to Dock. Apple's article, which requires macOS Sonoma 14 or later, states that the result is saved to the Applications folder of the home folder, so it appears in Spotlight, holds a Dock position and is reachable through Cmd+Tab. The settings panel inside the window allows the name, the icon and the URL to be changed, lets the navigation controls be hidden, and carries an Extensions tab where Safari extensions can be switched off for that window alone.

That last detail is the one worth acting on here. Turning extensions off for a single window is exactly the isolation ID.me's troubleshooting pages keep asking for, without disabling anything in the browser used for everything else.

Where the built-in route runs out is session control. A Safari web app uses Safari's engine and its own store, which is fine for one account. A site to app tool covers the cases beyond that: a window that keeps a session entirely of its own, a second window for a second wallet on the same host, and a choice of engine when a site behaves better in one than another. The supported services list shows the pattern applied across the sites people most often pull out of a tab strip, and a sign-in page used once a week sits in the same family as mail and banking.

What to test in the first ten minutes

Three checks settle whether the window is doing its job. Register the passkey inside the new window rather than in Safari, then quit the window and reopen it to confirm the sign-in still completes. Confirm the window survives a restart with the session intact. And keep one alternative MFA method live during the test, because a passkey bound to a window that gets deleted is a lockout waiting to happen.

Household accounts are separate windows, not separate logins

ID.me accounts are personal by design, and a single household often has two or three of them, for a veteran's benefits, a tax filing and a discount programme. A browser profile holds one signed-in session per site, so two wallets in one browser means signing out and back in, or keeping one in a private window that forgets everything on close.

The passkey rule makes this sharper than it looks. Each device can be linked to only one wallet per ID.me's own documentation, and the passkey is tied to the browser it was created in. Two windows, each with its own session store, is the arrangement that lets two wallets coexist on one Mac without either one being logged out to reach the other. Anyone in that situation should check how many separate windows a setup allows before committing to the approach.

What to change first

Open the ID.me Wallet, go to Sign In & Security, and add passkey as a second method while keeping the existing one in place. Then decide where that sign-in page is going to live, because a passkey is bound to the browser that created it, and if the answer is a window of its own rather than a tab, Kagemusha is one way to build it.

Frequently asked questions

Is there an ID.me Authenticator app for Mac?

No. ID.me's help documentation lists two download routes for the Authenticator app, the iOS App Store and Google Play, and the App Store listing states "Requires iOS 12.0 or later" with a device list of iPhone, iPad and Apple Watch. There is no Mac entry on the listing and no separate macOS application from ID.me, Inc. On a Mac the sign-in happens on the ID.me website.

Can ID.me be used without a smartphone at all?

Yes, with two of the six MFA methods. Passkey uses the unlock method on the computer itself, such as a fingerprint or a device PIN, and a USB security key is tapped on the machine. ID.me rates both as very strong. The code generator and push notification methods both require the Authenticator app, which only exists on phones and tablets.

Does the ID.me code generator work in a desktop authenticator app?

ID.me does not document it. The code generator is set up by scanning a QR code with the ID.me Authenticator app, and the help article for that method names only the App Store and Google Play as download sources. Codes rotate every 30 seconds according to the same article. Anyone wanting a phone-free method should look at passkey or a security key instead, both of which ID.me supports directly.

Why does ID.me say it cannot verify the browser?

ID.me's help article on that message gives two causes: the browser is blocking a required security check, or JavaScript is switched off. The suggested fixes are to try a different browser, try a different device, and confirm JavaScript is enabled. In practice a heavily extended main browser is the usual culprit, which is why signing in from a window with extensions disabled for that window alone tends to clear it.

Will a passkey still work if the dedicated window is deleted?

Not reliably. ID.me states that a passkey is registered per device and warns that switching browsers between setup and sign-in can cause failures, so a passkey created inside one window is tied to that window's store. Keep a second MFA method active before deleting anything, and re-register the passkey from the new window afterwards.

Back to all posts