Wittigo

Engagement & Classrooms · All Roles

Icon Passphrase Authentication

Secure your classroom with visual passphrases — icons instead of passwords. Students pick 2 icons to verify their identity.

Icon Passphrase Authentication replaces traditional passwords with a visual system designed specifically for young students. Instead of typing a password or remembering a PIN, each student creates a unique passphrase by selecting two icons in sequence. This eliminates the friction of forgotten passwords while maintaining security for classroom activities, wallet access, and course participation.

For Teachers — How It Works

When you add a student to a classroom in the Engagement section, Wittigo automatically generates a 2-icon passphrase for them. Each student is assigned two random icons from a pool of 40, along with a unique cryptographic salt. The passphrase is stored as a SHA-256 hash — your school never stores plain-text icon selections. You can view any student's card by clicking the kebab menu (⋮) and selecting "View Card". The card shows the student's name and their two icons, ready to be printed or shown on screen.

Student Passphrase Card

Each student has a passphrase card that looks like this:

  1. Top: Student's full name in large text
  2. Middle: Two large icons displayed side-by-side with a "+" between them (e.g., 🐶 + 🌟)
  3. Bottom: A reminder that the student uses these icons in order to verify their identity
  4. Teachers can print individual cards or print all cards at once from the classroom view

Managing Passphrases

From the Engagement page, open a classroom to see your student list. Each student row shows a small shield icon indicating whether they have a passphrase configured (green = ready, gray = not set). Click the kebab menu (⋮) on any student to access these actions:

  1. View Card — See the student's passphrase icons in a printable card layout
  2. New Passphrase — Regenerate a fresh 2-icon combo (invalidates the old one immediately)
  3. At the top of the student list, use "Regenerate All" to refresh all passphrases at once, or "Print All Passphrases" to print every student's card in a compact grid layout

For Students — How to Use It

When you join a game or access a course in your classroom, you may be asked to verify your identity with a passphrase. This tells Wittigo that you are really you. The passphrase is your two secret icons.

  1. Step 1 — You will see a grid of 40 icons. Find your first icon and tap it.
  2. Step 2 — The grid reappears. Find your second icon and tap it.
  3. That is it! If you picked the right two icons, you are verified and can join the game or access the content.
  4. You have 3 attempts per minute. If you run out, wait 60 seconds before trying again.

Device Trust ("Remember Me")

On trusted devices (like a classroom tablet you use every day), you can check "Remember me until 4pm" after verifying your passphrase. This skips the icon picker for the rest of the school day on that device. Your teacher can disable this at any time by regenerating your passphrase.

Security & Privacy

Icon Passphrase Authentication is designed with student privacy as a priority. Passphrases are stored as SHA-256 hashes — raw icon selections are never stored server-side. Rate limiting (3 attempts per 60 seconds) prevents guessing attacks. Device trust tokens expire automatically at 4pm each day. No email or personal information is required to set up a passphrase.