pr0dDOCS
Identity

Sign-in methods

Email, Apple, Google, X, Privage, passkeys, and QR code. Turn on the ones your users expect.

Each application chooses its own set of methods. The sign-in screen shows only the methods you have turned on, in a layout you control.

MethodHow it works
EmailThe user enters an address and receives a six-digit code. No password.
AppleSign in with Apple. The user returns to your app with a verified account.
GoogleSign in with Google.
XSign in with an X account.
PrivageSign in with a Privage identity.
PasskeysA passwordless sign-in backed by the user's device. Phishing-resistant, and already multi-factor.
QR codeThe user scans a code with a device that is already signed in, then approves the new login there. Codes last two minutes.

Email codes

Email is the most common starting point. The code is six digits and is entered in a single step; a complete code verifies itself, and a pasted code is accepted as long as it contains six digits.

Social providers

Apple, Google, X, and Privage each return a verified account to your application. You can offer any combination, and the sign-in screen lays the buttons out in a row or stacked, one per line.

Passkeys

A passkey sign-in is passwordless and tied to the user's device. Because it already proves possession and presence, pr0d does not ask for a second factor after a passkey sign-in. Passkeys can also be used as a second factor on their own; see Multi-factor.

QR code

QR sign-in moves an existing session to a new device. The new device shows a code and a six-digit confirmation number; the signed-in device scans the code, checks that the number matches, and approves or declines. A declined or expired code leaves the new device signed out.

On this page