Welcome back
Sign in to your vault. All sessions are JWT-protected with refresh token rotation.
Create your vault
One account. Full JWT security stack — access tokens, refresh rotation, and 2FA.
Verify identity
Enter the 6-digit code from your authenticator app. Code refreshes every 30 seconds.
Reset your key
Enter your email and we'll send a signed, expiring reset link. Valid for 15 minutes only.
Access Token
JWT signed with HS256. Expires in 15 minutes to minimise exposure window.
Refresh Token
HttpOnly cookie. Rotates on every use — old tokens are immediately blacklisted.
Rate Limiting
5 attempts per 15 min per IP. Progressive delays prevent brute-force attacks.
Two-Factor Auth
TOTP-based second factor via authenticator app. Adds a critical layer on top of passwords.
Gaurav Kumar
gaurav@example.com
Live view of your current access token — decoded in-browser. The signature is never transmitted to untrusted clients.
Header
Payload
Scan this QR code with Google Authenticator or Authy.
Secret: JBSWY3DPEHPK3PXP