Sign in
Operator console. Passkeys only — no password, no code, no SMS.
Your passkey never leaves your device. The server receives a signature, not a secret.
Production The live console, not a staging copy.
A short label for the team page. No browser or device details are collected.
Enrolls the owner's first passkey. The token is refused while the owner still has a passkey, so it only works on a fresh console or after every owner passkey is gone. The owner address is the one set as ADMIN_OWNER_EMAIL.
Paste the one-time token the owner handed you. It works once and expires 72 hours after it was issued; if it has lapsed, ask the owner for a new one.
No codes for this console. Staff sign in with a passkey only; a code offered for admin.validthru.app is not from us. Customers do receive sign-in codes from the app.
Attempt limits. Ten attempts a minute, per IP address and per email, for sign-in and enrollment alike. Past the limit the console answers the same way whatever was entered.
Lost your passkey? Operators: the owner removes you on the team page and creates a new invite; your audit rows stay. Owner: the bootstrap token works again only once no owner passkey remains — see the runbook. There is no self-serve reset.