Accounts and sessions, honest by default

Everything behind a login. Sign-up, sign-in, email verification, password reset, as a library you embed rather than a service you rent. Secure by default, sessions you can end instantly, one account id the whole family shares. It already runs this site.

Try it on QuxCloud live demo · nothing to install
Open source
identity-kit crystal
Instant
sign-out: end a session and it is over on the very next request
0
secrets stored in a form anyone could read, your own team included
0
opt-in extras: two-factor, API keys, and Sign in with Google or Apple
1
account id the whole family shares. One person, one identity, everywhere
What it is

One library, whole, not a platform you rent

Passwords, handled

Modern password protection you never have to configure or second-guess. A copy of your database is not a copy of your customers’ accounts.

Sign-out that means it

Sessions live on your side, so ending one actually ends it, not a token you hope expires before anyone notices.

The flow never tells

Sign-up, sign-in and reset answer the same way whether or not an account exists, so nobody can fish for who your customers are.

One identity, everywhere

A single account id the rest of the family keys on, so a person is the same person across billing, teams and email.

Two-factor, when you want it

Available per account and off by default. A security upgrade you can offer, not a wall you make everyone climb on day one.

Google and Apple sign-in

Social sign-in with a clear rule for when two logins are the same person. An extra front door, not a back one.

By the shape of it

A session you cannot end is a promise you cannot keep.

3 factors
45% Password
30% MFA
25% API key

A password, a second factor, a scoped key: layered, and each one optional.

How it works

Three moves, in order

01
Verify

Check the password or the social sign-in, without ever revealing whether that account exists.

02
Issue

Start a session for that account, stepping up to a second factor if you have asked for one.

03
Revoke

End any session on demand. Because it lives in your database, it is over immediately.

identity-kit.ts
import { signup, login, sessions } from '@quxkit/identity-kit';

// the flow answers the same way whether or not the account exists
const user = await signup(sql, { email, password, pepper });

// sessions live on your side, so ending one actually ends it
const session = await login(sql, { email, password, pepper });
await sessions.revoke(sql, session.id);
“

A session you cannot end is a promise you cannot keep.

Run it now, embed it later