Sign in
We email you a link. No password to choose, forget, reuse or leak.
Why there is no password
Nothing to steal
There is no password hash in the database, so a breach of it cannot be replayed against your other accounts.
Same proof, less ceremony
A password reset is already an emailed link. This removes the step that pretends otherwise.
Links expire and work once
Fifteen minutes, single use. A link found later in a mailbox archive is worthless.
Your mailbox is the account
Which is worth stating plainly: anyone who can read that inbox can sign in. Protect it accordingly.