Login.gov is the U.S. federal government's shared authentication service, operated by the General Services Administration's Technology Transformation Services. One account signs a user into participating agency services — IRS tools, Social Security access, USAJOBS, state benefits portals using the service through partnerships — and the platform reported passing tens of millions of users as federal services migrated to it through the 2020s. The engineering idea is standard; the policy idea is significant. Before shared sign-on, every agency built its own identity machinery, with inconsistent security and, for users, one password policy per agency. Login.gov centralizes the credential — something the user knows and has — while leaving the account relationship with the agency.
How the sign-on actually works
The service separates two jobs that consumer systems blur. Authentication confirms the credential: password plus a second factor, with phishing-resistant options such as WebAuthn security keys supported for stronger protection. Identity proofing — establishing that the account belongs to the real person behind a Social Security number or state ID — is a separate, stricter ladder defined by the National Institute of Standards and Technology's Digital Identity Guidelines, SP 800-63, at assurance levels from minimal to IAL2, which requires verifying against authoritative records or documents. Agencies choose the level their program requires: signing in to see a job posting needs less proofing than accessing tax records or claiming benefits.
Where it got hard
The 2024 inspector-general reporting on Login.gov — the GSA Office of Inspector General found the service marketed IAL2 compliance before fully meeting the standard's requirements, and GSA subsequently refunded fees to affected agencies — matters less as a scandal than as a map of the difficulty. Identity proofing at population scale runs into exactly the people who most need government services: applicants without standard documents, credit-file thinness that defeats knowledge-based verification — a method NIST itself deprecated for its insecurity — address mismatches, and name changes. Every proofing shortcut creates fraud exposure; every strictness creates exclusion. The documented equilibrium: equity reviews of remote proofing consistently find verification-failure rates higher for younger, poorer, and recently moved applicants, which is why NIST's revision work on SP 800-63 keeps equity testing in scope.
Why agencies keep joining anyway
The alternative is worse on every axis an agency chief information officer owns. Agency-built systems duplicated credential storage — each one a breach target — and duplicated the accessibility, security-authorization, and lifecycle work under the Federal Information Security Modernization Act and FedRAMP requirements. A shared service amortizes that across government: one incident-response team, one phishing-resistant rollout, one accessibility program, with agencies consuming sign-on through documented APIs. For users, the win is memory and trust: one account, one recovery flow, and a login page that looks the same at every agency.
What to watch next
Two developments will decide whether the service becomes invisible infrastructure or a bottleneck. First, mobile driver's licenses and digital credentials: state mDL programs conforming to ISO 18013-5 could replace document-photo proofing with cryptographic verification, though state adoption is uneven. Second, the fraud pressure: benefits programs attacked through identity theft during pandemic-era relief, documented in GAO and Pandemic Response Accountability Committee reporting, pushed agencies toward stricter proofing, and the exclusion cost of that strictness is the policy argument that will not go away.
FAQ
What is Login.gov?
A General Services Administration-operated service providing one secure account for signing in to many federal and partner state services, with two-factor authentication and optional identity proofing.
What is identity proofing versus authentication?
Authentication verifies your credential each sign-in; identity proofing, per NIST SP 800-63, verifies once that the account belongs to the real person, at assurance levels agencies choose per program.
Was there a Login.gov compliance problem?
GSA's inspector general found in 2024 the service was marketed as meeting the IAL2 proofing standard before fully doing so; GSA refunded fees and completed remediation.
For more context, read FedRAMP: How a Cloud Service Gets Federal Authorization.
For more context, read government payment delivery.
For more context, read us digital service.
