Sign-in methods
Email, Apple, Google, X, Privage, passkeys, and QR code. Turn on the ones your users expect.
Each application chooses its own set of methods. The sign-in screen shows only the methods you have turned on, in a layout you control.
| Method | How it works |
|---|---|
| The user enters an address and receives a six-digit code. No password. | |
| Apple | Sign in with Apple. The user returns to your app with a verified account. |
| Sign in with Google. | |
| X | Sign in with an X account. |
| Privage | Sign in with a Privage identity. |
| Passkeys | A passwordless sign-in backed by the user's device. Phishing-resistant, and already multi-factor. |
| QR code | The user scans a code with a device that is already signed in, then approves the new login there. Codes last two minutes. |
Email codes
Email is the most common starting point. The code is six digits and is entered in a single step; a complete code verifies itself, and a pasted code is accepted as long as it contains six digits.
Social providers
Apple, Google, X, and Privage each return a verified account to your application. You can offer any combination, and the sign-in screen lays the buttons out in a row or stacked, one per line.
Passkeys
A passkey sign-in is passwordless and tied to the user's device. Because it already proves possession and presence, pr0d does not ask for a second factor after a passkey sign-in. Passkeys can also be used as a second factor on their own; see Multi-factor.
QR code
QR sign-in moves an existing session to a new device. The new device shows a code and a six-digit confirmation number; the signed-in device scans the code, checks that the number matches, and approves or declines. A declined or expired code leaves the new device signed out.