AUTH.00
Ten doors, one engine

Every one of these really signs you in.

Same tokens, same brand, same engine — only the form changes. Use the dashes below, or the left and right arrow keys.

Sign-in style preview

01 / 10
Style

When to use it

Technically

Decision
What the engine can do

Every way in, and where it stands.

A style is a shape. This is the substance behind it — and what is honestly not switched on yet.

Sign-in methods and their state
Way inWhat it isState
Magic linkOne-time link by email, valid five minutes.live
6-digit codeSame mail, for the device that cannot open the link.live
GoogleFederated OIDC. Measured 2026-08-23 through to the Google sign-in page.live
GitHubFederated OAuth. Same measurement.live
LinkedInFourth provider, enabled per app in the database. No PKCE on their side, no revoke endpoint.live
AppleProvider exists in the engine; no developer app registered, so no button.not usable
Passkey (WebAuthn)Discoverable credentials, no username needed.planned
TOTP second factorAuthenticator app for accounts that want it.planned
DPoP / PARSender-constrained tokens, request pushed ahead of the redirect.planned
Step-upAsk again before a sensitive action, not at the door.built, not shipped
Agent sign-inclient_credentials plus RFC 7591 self-registration, rotating revocable keys.built, not merged
Per-tenant allowlistApp answers only to listed addresses, on every provider.staging only
White-label tenantOwn wordmark, own accent, own domain — data, not a redeploy.live
Device codeFor screens without a keyboard: code here, confirm there.not built
Enterprise SSO (SAML)What large customers ask for in procurement.not built
SMS codeDeliberately not offered — SIM swapping, per-message cost, no gain.not planned

State read from the house state files on 2026-08-24; the three live providers were measured against the engine the same day. Anything marked planned or not built has no button anywhere — a button that does nothing is worse than no button.