Skip to content
Passkin
Sign-in for developers

Skip the OAuth consoles.
Ship sign-in today.

Google, GitHub and email codes on Passkin's verified apps — no client ids to register, no consent screen to get reviewed, no secrets to rotate. Standard OpenID Connect, for your website and your iOS, Android and desktop apps, in Arabic and English.

Nothing to register

Passkin's Google and GitHub apps by default. Your own, whenever you want.

Standard OIDC

Your own issuer and signing key. Any library, any language.

Websites and apps

One project, one set of users, every platform.

Free during early accessNo credit cardYour own keys optional
Google sign-in on Passkin's app

Walk through what happens between the click and a signed-in person — every step is one the service really takes.

  1. Press “Run a sign-in”.

Works with

Next.js React and any SPA iOS Android Desktop Any OpenID Connect library
How it works

The work you no longer do

Sign-in is a week of consoles, secrets and edge cases before the first person signs in. Passkin has already done it, once, for everyone.

Doing it yourself

Before the first person signs in

  • Register an OAuth app at Google, another at GitHub — one per environment
  • Fill in Google's consent screen, publish it, wait for review
  • Store client secrets, rotate them, keep them out of git
  • Implement PKCE, state, nonce, token refresh and its rotation
  • Build the email-code flow: generation, expiry, attempts, deliverability
  • Build a sign-in page, in Arabic too, right to left

With Passkin

Four steps, then back to your product

  1. 1.Create a project: a publishable key and your own OpenID Connect issuer
  2. 2.Add your site's redirect URL
  3. 3.Paste three files, or one script tag
  4. 4.Switch methods on and off in the dashboard — no deploy

Every website and app of a project shares its users: sub is the same person on the website and in the iPhone app, and your API checks one kind of token.

Playground

See your sign-in page

This is the page your users get — the same layout and words. Switch methods, change the language, open it from an app, and press the buttons.

Sign-in methods

3 on
Coming next
ApplesoonMicrosoftsoonLinkedInsoonXsoonFacebooksoonDiscordsoon
Where
Language
Your button opens
Device
Accent
auth.passk.in/signin/…
A
Acme
acme.com

Sign in to Acme

to continue

or
you@example.com
Cancel
Secured by Passkin · العربية
What your site opens
https://auth.passk.in/p/pk_live_…/authorize?client_id=pk_live_…&redirect_uri=https://acme.com/api/auth/callback&response_type=code&scope=openid+email+profile&code_challenge_method=S256&code_challenge=…&state=…

The SDK builds this for you. connection=email opens straight on the email form; connection=google skips the page entirely.

Every platform

Your website and your apps, one set of users

Add each as an application of the same project. Each gets its own client id; all of them share the people.

Websites

Next.js SDK — the session in an encrypted cookie on your server, refreshed for you. Any other server: any OpenID Connect library.

Single-page apps

widget.js with one script tag, or oidc-client-ts. No secret in the browser: PKCE protects the exchange.

iPhone and iPad

Your own buttons open Passkin in the system sheet over the app (ASWebAuthenticationSession). Sign in with Apple's own sheet, optional.

Android

Custom Tabs over the app — or the phone's own Google account sheet, with Passkin registering your app at Google for you.

Desktop

The system browser and a loopback redirect, the way RFC 8252 says a native app should sign in.

Optional

Start with no keys.
Bring your own when you want.

Passkin's apps are the default, and they are enough to run in production. Your own Google or GitHub app is there for one reason: your name on the provider's screen instead of Passkin's.

Nobody signs up again

People are matched by the provider's account and their verified email, so switching keeps every user and their id.

One callback for everything

Your own app registers auth.passk.in/callback/google — the same for your website and every app.

Switch back any time

Your keys are encrypted at rest; remove them and the project is on Passkin's apps again.

Google, in Sign-in methodssame users

Passkin's app

Google's screen says “Passkin”. Nothing to set up.

Default

My own app

Google's screen says your name. Client id and secret from your Google Cloud.

Optional

GitHub works the same way

Passkin's OAuth app, or yours.

Arabic and English

Built for both directions

The sign-in pages follow the person's language — or the one your app asks for with ui_locales — right to left where it should be, with Latin addresses kept readable.

English
A
Acme
acme.com

Sign in to Acme

to continue

or
you@example.com
Cancel
Secured by Passkin · العربية
العربية
م
متجر الواحة
alwaha.sa

سجّل الدخول إلى متجر الواحة

للمتابعة

أو
you@example.com
إلغاء
الدخول عبر Passkin · English
Security

Written down, and tested

  • PKCE (S256) for every client; codes single-use, bound to the client and redirect URL
  • Redirect URLs compared exactly — never by prefix
  • Sessions, codes and refresh tokens stored hashed; a reused refresh token ends the session
  • Sign-in pages with no JavaScript, a strict CSP, and no framing
  • The sign-in page shows the domain or app that will receive the person
  • Each project signs with its own key; a person's id is different on every project
  • An unverified email never links to an existing account
  • A production start refuses an unsafe configuration

Each of these has a test. The whole model is in the security notes.

Developer experience

The code you paste

The dashboard shows each application these snippets with its own keys filled in.

// lib/passkin.ts
import { createPasskin } from "@unipass/nextjs/server";
export const { handlers, auth, currentUser, protect, verifyRequest } = createPasskin();

// app/api/auth/[...passkin]/route.ts
import { handlers } from "@/lib/passkin";
export const { GET, POST } = handlers;

// middleware.ts
import { passkinMiddleware } from "@unipass/nextjs/middleware";
export default passkinMiddleware({ protect: ["/dashboard"] });

// app/layout.tsx — <SignInButton />, <UserButton />, useUser() anywhere below
<PasskinProvider initialUser={await currentUser()}>{children}</PasskinProvider>
Pricing

Free during early access

No card, no plan to pick. Everything below is included.

Early access

For every project you create now.

$0
  • Google, GitHub and email codes
  • Passkin's apps, or your own
  • Websites, SPAs, iOS, Android, desktop
  • Native Google and Sign in with Apple in apps
  • Users, sessions, bans, activity log
  • Backend and Management APIs
  • Your logo, colour, Arabic and English
  • Development and production projects
Create a project
Answers

Questions developers ask

No. Every project starts on Passkin's verified apps: switch Google or GitHub on and it works, on your website and in your apps. If you want your own name on Google's consent screen, bring your own client in Sign-in methods — it is optional, and your users keep their ids.

Sign-in, done.
Back to your product.

Create a project, add a redirect URL, paste three files. Your first user can sign in in minutes.