Short-lived by default.
Tokens measured in minutes, refreshed quietly. A leaked credential is a closing window, not a standing grant.
Why the gate holds
Everything else on the platform can fail gracefully; identity cannot. So Weke ID is built on the assumption that every input is hostile, every token will leak eventually, and every shortcut will be found.
Credentials go to this origin and nowhere else — the sign-in page's policy forbids inline code, third-party hosts, and any form action that is not this server.
Fifteen minutes of session, and an audience grant only when a console asks for one. There is no long-lived, all-doors token to steal.
The public keys are published; verification is local to each service. Weke ID cannot silently vouch for anyone — the signature either checks or it doesn't.
Tokens measured in minutes, refreshed quietly. A leaked credential is a closing window, not a standing grant.
It is posted once, to this origin, over TLS — never embedded in a URL, never forwarded to another host, never seen by the console you are entering.
Sign-in, reset, and verify share one visual identity across all twelve surfaces. A door that looks unfamiliar is the phishing tell — so no legitimate door ever does.
At the door
The reset page answers neutrally whether the address exists or not, and the emailed link is single-use with an expiry — recovery is a door, so it gets the same walls.
