Token, a leader in biometric assured identity, announced that its TokenCore Wearable and TokenCore Portable products provide Salesforce customers, Salesforce partners, and Salesforce administrators with one of the strongest available methods for meeting and exceeding Salesforce phishing-resistant access requirements.
Salesforce has made clear that the security landscape has changed. AI-driven phishing, vishing, social engineering, credential theft, and account takeover attacks are putting Salesforce users and Salesforce data at increasing risk. Salesforce has also announced stronger security requirements, including MFA for employee users and phishing-resistant MFA for privileged users, including Salesforce admins.
Token directly addresses this new Salesforce security reality by combining biometric identity, phishing-resistant FIDO2 and WebAuthn authentication, secure hardware, and wireless ease of use. Token products are designed to ensure that Salesforce access is granted only when the authorised physical human is present and biometrically verified.
“Salesforce is raising the bar for identity security, and that is exactly where the market needs to go,” said Kevin Surace, CEO of Token. “Salesforce holds some of the most valuable business data in the enterprise. Protecting Salesforce access with legacy MFA, push approvals, SMS codes, shared passwords, or cloud-synced software credentials is no longer enough. Token gives Salesforce customers biometric assured identity for Salesforce access today.”
Token products support phishing-resistant authentication by using FIDO2 and WebAuthn protocols that bind authentication to the legitimate Salesforce login origin. Unlike SMS codes, authenticator apps, push approvals, or shared passwords, Token does not give attackers a code to steal, a prompt to trick, or a password to relay. Each authentication event requires the registered Token device, the authorised user’s fingerprint, and a cryptographic challenge tied to the legitimate service.
The result is Salesforce access that is not merely based on something a user knows or something a user possesses. The token verifies the actual person.


