People
Signing in
Passkeys first, magic links as a fallback, a second factor for money, and codes for devices.
| Way in | When | What the person does |
|---|---|---|
| Passkey | Default, every device | Face ID, Touch ID, Windows Hello or the phone’s unlock. Works across phone and laptop. |
| Magic link | No passkey on this device yet | Clicks a link sent to their email. |
| Second factor | Before moving money or minting keys | Confirms with an authenticator code on a page hosted by OpenPulse. |
| Recovery codes | Authenticator lost | Uses a one-time code instead of the authenticator code when a second factor is asked. |
| Lost device | No passkey available | Signs in with a magic link, then adds a passkey on the new device. |
| Device code | CLIs, TVs, headless machines | Opens openpulse.org/auth/device on another device and approves with a passkey. |
What they see#
Sign-in happens on openpulse.org/auth, or on your own domain if you set one up (for example login.acme.com), with your realm’s name and branding. After it, they land back where they started in your app.
Sessions#
A sign-in lasts up to 30 days and ends after 14 days without use. People see and end their sessions on their identity page. Security events (a new passkey, new recovery codes) are sent to them by email.