PairCodeAccess control

Present your credential

PairCode issues every operator a verified identity before they reach a room. Sign in and the server — not this page — decides what you may read, write, and administer inside it.

What the door enforcesIn this repository
Password storage
Argon2idlib/auth/password.ts
Access tokens
EdDSA (Ed25519) JWTlib/auth/jwt.ts
Refresh tokens
Rotated, reuse detected and revokedlib/auth/refresh.ts
Form submission
CSRF token, double submitlib/auth/csrf.ts
Socket handshake
Single-use ticket, redeemed by deletelib/security/ws-ticket.ts
Room authorization
Server-side RBAC on every eventserver/ws-server.mjs

No third-party auth service sits behind these rows.

Present credential
??
Bearer

Unissued

no identity presented

or

A visitor pass is a real, short-lived guest session. It opens rooms you create; it is not a demo mode.

No account yet? Apply for one