A pass, not a password
A code to your email or phone gets you into every app we make. One page shows where you're signed in, who's on your team, and lets you sign out of everything.
Free for the apps we make. Nothing to remember, nothing to recover.
One pass is valid at
Your pass, in your hand
Every device you're signed in on, every teammate and their role, every key you made and every app you allowed. Each one has an undo.
key_d13759a2 · celdrivekey_7c0e21ab · unyplexkey_32ff90de · pentasorHow it works
We send a 6-digit code. It works once and expires in 10 minutes.
That's the whole sign-in. Your session lasts 30 days on that device.
Every app in the family reads your pass. One account, one team, everywhere.
What a pass guarantees
No passwords exist. Codes, sessions, keys and tokens are stored as one-way hashes; the real value is shown once.
Email through mailvak, texts through linevak. passvak holds no email or SMS credentials at all.
Accounts and teams are exported every day to storage nothing can delete for 30 days — not us, not an attacker.
Everything we hold about you is one download away, and deletion is a button, not an email to support.
The last 50 sign-ins and changes, with device and time, so a sign-in you didn't make stands out.
For developers
Standard OAuth 2.1 with PKCE. Send the person to passvak, get back who they are and which teams they're in. API keys scoped to your product come with it.
# 1 · send them to passvak
GET https://api.passvak.com/oauth/authorize?client_id=yourapp
&redirect_uri=https://yourapp.com/cb&code_challenge=…&code_challenge_method=S256
# 2 · exchange the code
POST https://api.passvak.com/oauth/token → { access_token, refresh_token }
# 3 · read who they are
GET https://api.passvak.com/me → { account, teams, key.product }
Open your account page and sign in with a code. There is nothing to set up.