Look.
You’re in.
Face ID sign-in for any site. A WhatsApp code the first time, a glance every time after. No passwords.
Loma Coffeeon WhatsApp
first visitHi Marina 👋 Your sign-in code is 482 913
Once. Then it’s Face ID.
Sign in to Loma Coffeeevery visit
Face ID
One look. No codes.
Welcome back, Marina.
Signed in with Face ID.
One look, not a password.
Fallback lives in WhatsApp.
One snippet, any site.
<script src="https://auth.okia.io/js/v1.js">
Sixty seconds, once.
Enter a number
A code lands in WhatsApp.
Tap once
Face ID is saved for next time.
Done forever
Every visit after is a glance.
One you. A different ID for every site.
Sites never see a phone number, and can never compare notes.
loma.coffee
sub pw_8f3a91c2
vela.store
sub pw_c21d447e
Nothing to steal.
Nothing to phish
Face ID keys answer only to the real domain. A fake site gets nothing.
Nothing to breach
No passwords stored. Keys never leave the device.
Nothing bespoke
Standard OAuth2 and OIDC. ES256 tokens, public JWKS.