All Weke consoles Open your account

The front door

The front door, engineered.

Every console launches the same hosted sign-in. Before a single field renders, the page asks the server whether the app and return address are legitimate — and if they are not, no form ever appears.

Through the gate, trailing 12 weeks Illustrative fixture data.
Through the gate, trailing 12 weeks
  • Sign-ins
  • 2FA challenges
  • Rejected launches
01 / Context

The page checks before it asks

An unknown audience or a disallowed return address gets a dead end, not a form. Credentials are never collected for a destination the server has not vouched for.

02 / 2FA

A second factor when it matters

Accounts with two-step verification get the TOTP challenge in the same card — with backup codes for the day the phone is gone.

03 / Hardening

Locked down by policy

The sign-in page runs under its own strict CSP — no inline code, no third-party hosts, no framing — with a rate limiter watching the one endpoint that does real work.

At the door

The door every console shares

The hosted sign-in in the platform's research-editorial language — serif heading, aurora, blueprint grid, and the name of the console you are entering.

The hosted Weke ID sign-in page with aurora backdrop and serif heading