A pass, not a password

One pass for everything.

A code to your email or phone gets you into every app we make. One page shows where you're signed in, who's on your team, and lets you sign out of everything.

Free for the apps we make. Nothing to remember, nothing to recover.

One pass is valid at

CCelDriveUUnyplexmmailvakPPentasor+Your app, with Sign in with passvak

Your pass, in your hand

One page for every app, instead of a settings screen in each.

Every device you're signed in on, every teammate and their role, every key you made and every app you allowed. Each one has an undo.

passvak.com/account

Where you're signed in 3 devices

  • Safari · MacOct 6 · email · 190.80.x
    this device
  • Safari · iOSOct 5 · phone · 190.80.x
    Sign out
  • Chrome · WindowsSep 28 · email · 152.0.x
    Sign out
Sign out everywhere

Your team Panadería Luna

  • Ana Pérezana@example.com
    owner
  • Bob Martebob@example.com
    admin
  • Carla Núñezcarla@example.com
    member
Invite →

Your keys

  • laptopkey_d13759a2 · celdrive
    Revoke
  • cikey_7c0e21ab · unyplex
    Revoke
  • agentkey_32ff90de · pentasor
    Revoke

How it works

Three steps. Nothing to remember.

1

Type your email or phone

We send a 6-digit code. It works once and expires in 10 minutes.

2

Type the code

That's the whole sign-in. Your session lasts 30 days on that device.

3

Use any app

Every app in the family reads your pass. One account, one team, everywhere.

What a pass guarantees

Built the way an identity service should be.

Nothing to steal

No passwords exist. Codes, sessions, keys and tokens are stored as one-way hashes; the real value is shown once.

Codes travel on our own rails

Email through mailvak, texts through linevak. passvak holds no email or SMS credentials at all.

Backed up, locked, daily

Accounts and teams are exported every day to storage nothing can delete for 30 days — not us, not an attacker.

Export and delete, no request

Everything we hold about you is one download away, and deletion is a button, not an email to support.

A sign-in log you can read

The last 50 sign-ins and changes, with device and time, so a sign-in you didn't make stands out.

For developers

"Sign in with passvak" is one redirect.

Standard OAuth 2.1 with PKCE. Send the person to passvak, get back who they are and which teams they're in. API keys scoped to your product come with it.

sign-in-with-passvak
# 1 · send them to passvak
GET https://api.passvak.com/oauth/authorize?client_id=yourapp
    &redirect_uri=https://yourapp.com/cb&code_challenge=…&code_challenge_method=S256

# 2 · exchange the code
POST https://api.passvak.com/oauth/token            → { access_token, refresh_token }

# 3 · read who they are
GET  https://api.passvak.com/me                     → { account, teams, key.product }

Ready when you are.

Open your account page and sign in with a code. There is nothing to set up.