Most accounts never set a password at all — a one-time code, sent to the address your institution registered, is the way in. Sessions live in rotating refresh-token families with reuse detection, and every device that touches the account is recorded and revocable.
One-time codes, no password to lose
Refresh-token reuse detection
Revocable per-device sessions
A known address and an unknown one are answered identically. The API never confirms who has an account here.
Sign in
Enter your email address and we will send you a code. No password needed.
Trouble signing in? Contact your organisation’s administrator.