Skip to content
OpenPulseDocs

People

Signing in

Passkeys first, magic links as a fallback, a second factor for money, and codes for devices.

Way inWhenWhat the person does
PasskeyDefault, every deviceFace ID, Touch ID, Windows Hello or the phone’s unlock. Works across phone and laptop.
Magic linkNo passkey on this device yetClicks a link sent to their email.
Second factorBefore moving money or minting keysConfirms with an authenticator code on a page hosted by OpenPulse.
Recovery codesAuthenticator lostUses a one-time code instead of the authenticator code when a second factor is asked.
Lost deviceNo passkey availableSigns in with a magic link, then adds a passkey on the new device.
Device codeCLIs, TVs, headless machinesOpens openpulse.org/auth/device on another device and approves with a passkey.

What they see#

Sign-in happens on openpulse.org/auth, or on your own domain if you set one up (for example login.acme.com), with your realm’s name and branding. After it, they land back where they started in your app.

Sessions#

A sign-in lasts up to 30 days and ends after 14 days without use. People see and end their sessions on their identity page. Security events (a new passkey, new recovery codes) are sent to them by email.