Sign in
Operator console. Passkeys only — no password, no code, no SMS.
Your passkey never leaves your device. The server receives a signature, not a secret.
Production Live data. Every view is logged.
The owner account is defined by the ADMIN_OWNER_EMAIL secret. The bootstrap token enrolls the owner's first passkey and is refused again until the owner has none.
Paste the one-time token the owner handed you. It works once and expires 72 hours after it was issued; if it has lapsed, ask the owner for a new one.
A short label for the team page. No browser or device details are collected.
There is no SMS sign-in. This console never sends codes by text or email. A message claiming to be Valid Thru and offering a code is not from us.
Attempt limits. Sign-in and enrollment attempts are limited to 10 per minute, per address and per email. When the limit is reached the console answers the same way regardless of what was entered.
Lost your passkey? Operators: ask the owner for a fresh invite from the team page. Owner: once no passkey remains, the bootstrap token enrolls a new one. There is no self-serve reset on this console.