VoiceID
Sign in by just speaking
Why
Passwords are the part of software nobody actually wants to think about, and they keep leaking. VoiceID is my attempt at a login with no password at all: an account is a username plus a voice. You record five short sentences once, and from then on signing in is reading one sentence into your microphone.
It's built on a real speaker recognition model, ECAPA-TDNN, running inside FastAPI, with the browser doing nothing but recording. I wrote three blog posts about it because the interesting work is mostly in the backend. The idea and frontend, the audio pipeline, and the verification itself.

How it works
- Record five short sentences at registration (different phrases each time, so the embeddings aren't near-duplicates)
- Each upload goes through ffmpeg (downsampled to 16 kHz mono) and Silero VAD (speech detected and trimmed)
- ECAPA-TDNN turns the cleaned audio into a 192-dimensional embedding
- Login compares the live embedding to the stored set with cosine similarity, and passes when the score clears a threshold
- No password, no email, no raw audio stored, the samples stay as vectors

Details
Built with Python and FastAPI on the backend, serving the speaker model behind a single endpoint. Next.js handles the browser side and proxies everything to the API so the session stays same-origin. Vectors live in PostgreSQL with pgvector, sessions are opaque tokens stored only as SHA-256 hashes, and rate limiting plus per-username lockout sit in front of the login.
One honest caveat: this is speaker verification, not liveness. Replaying a recording of the enrolled voice will pass. It's a great login for a demo and a terrible one for a bank.
Tech Stack
Built with Python, FastAPI, and Next.js. The source is on GitHub.