Webinar – Frictionless, Personal, On-Brand: Digital Experiences That Drive Results in 2026

Search PAR Engagement

Blogs

Introducing Advanced Authentication: A Smarter, More Secure Way to Welcome Guests

As the digital front door to your brand, your login experience needs to be both secure and seamless. That’s why we built PAR Advanced Authentication—a foundational upgrade to how your guests sign in across mobile apps, online ordering, kiosks, and even POS.

With next-gen identity flows that balance security and speed, Advanced Authentication gives developers more control, IT teams greater protection, and brand administrators the flexibility to tailor every experience—without needing engineering support for every change.

Let’s dive into how it works and how to get started.

What Is Advanced Authentication?

PAR Advanced Authentication is a new identity system that supports secure login across mobile ordering, online checkout, and POS check-ins. Built on a token-based infrastructure, it enables:
Whether you’re a developer implementing login flows or a brand administrator configuring the guest experience, Advanced Authentication is designed to work across your tech stack with ease.

What Problem Are We Solving?

Prior to Advanced Authentication, Punchh primarily used email and password logins for mobile and online platforms, while POS systems relied on phone number lookups handled by a cashier.

Advanced Authentication enhances this with a more secure method: One-Time Passwords (OTPs). These are sent via SMS or email, eliminating the need for persistent passwords and reducing the risk of credential theft.

Behind the scenes, we use Proof Key for Code Exchange (PKCE)—a widely accepted security protocol outlined in IETF RFC 7636—to protect each login request with verified tokens and code challenges.

Real-World Use: Mobile App Login

Here’s how the process works in a typical mobile app:

What’s Next: Expanding to New Channels

While the current release supports mobile applications, we’re actively working to bring the same secure, streamlined authentication experience to:

Implementation Details for Developers

If you’re integrating Advanced Authentication, here’s what your team needs to know about implementing it across your stack.

TL;DR – Software Changes at a Glance

Key API Calls:

Required Headers:

Handling Expired Tokens:

Deeper Dive: How It Works

In contrast to our previous single-call sign-in method, Advanced Authentication introduces a more secure, multi-step process:

All authenticated API requests now require both the access token and id token in the headers.

Developer Resources to Get You Started

Postman Collections

Our PAR Punchh Postman Collections provide ready-to-use API scenarios including:

You can explore these collections to see exactly how requests and responses should be formatted.

Sample Application (Coming Soon)

We’re also releasing a sample app in Python that walks you through:

Ask your PAR Punchh representative to request access.

Looking Ahead

Advanced Authentication is just the beginning of a more secure, flexible guest experience across all digital touchpoints.

Interested in being an early adopter or want a deeper walkthrough? Reach out to your Punchh team contact or connect with us on LinkedIn. We’d love to help you get started.

  • Anthony is a Content Manager at PAR Punchh, joining the team in 2023. A Philadelphia native, he holds an MA in Strategic Business Communications from La Salle University. When he's not crafting engaging content, Anthony enjoys eating, exercising, traveling, and playing volleyball and kickball. He is passionate about learning from others and exploring diverse perspectives.

Recent Posts

No posts found! Try adjusting your filters.

Explore these posts...

By Post Type:

By Taxonomy: