All Weke consoles Open your account

Why the gate holds

Identity, kept honest.

Everything else on the platform can fail gracefully; identity cannot. So Weke ID is built on the assumption that every input is hostile, every token will leak eventually, and every shortcut will be found.

  1. 01

    Prove it's you

    Credentials go to this origin and nowhere else — the sign-in page's policy forbids inline code, third-party hosts, and any form action that is not this server.

  2. 02

    Mint the smallest credential

    Fifteen minutes of session, and an audience grant only when a console asks for one. There is no long-lived, all-doors token to steal.

  3. 03

    Let every service verify

    The public keys are published; verification is local to each service. Weke ID cannot silently vouch for anyone — the signature either checks or it doesn't.

Sign-ins within policy Illustrative fixture data.
Sign-ins within policy
  • Verified sign-ins
  • Policy baseline

Short-lived by default.

Tokens measured in minutes, refreshed quietly. A leaked credential is a closing window, not a standing grant.

The password never travels.

It is posted once, to this origin, over TLS — never embedded in a URL, never forwarded to another host, never seen by the console you are entering.

Every door looks the same.

Sign-in, reset, and verify share one visual identity across all twelve surfaces. A door that looks unfamiliar is the phishing tell — so no legitimate door ever does.

At the door

Even forgot-password holds the line

The reset page answers neutrally whether the address exists or not, and the emailed link is single-use with an expiry — recovery is a door, so it gets the same walls.

The hosted Weke ID password reset page in the shared visual identity