Customer sign-in
Let customers sign in to a portal, invited or open to sign-up.
Plans: Every plan, including the free app
What you get
- Sign-in with an emailed code or a passkey
- Invite-only by default, or open to sign-up
- Sign-in pages and emails in the app's name
- One customer list per app, or shared by several apps
- Invite, block and remove customers
- Customers kept apart from your team and dashboard
How it works
You turn customer sign-in on with one line in the app's whisk.yaml. Customers sign in with an emailed code or a passkey, built on the WebAuthn open standard, on a page in the app's name. A customer account can never open your dashboard or the Whisk API.
A new portal is invite-only. An owner or admin invites customers from the dashboard, or the app invites them through Whisk's API as part of its own onboarding. An owner can open sign-up when anyone should be able to register.
Caddy, the open-source web server, checks every request, and the app reads the customer's ID and email from request headers. Blocking a customer takes effect on their next request. Your own staff keep their team sign-in.
Example
A freight forwarder gives each importer a portal to track shipments and download customs documents. The account manager invites each importer's contacts, who sign in with an emailed code the first time and a passkey after that. When a contact leaves the importer, the forwarder blocks them from the dashboard.
For your coding agent
customer_identity: app routes: public: ["/", "/health"]
Invite a first customer with whisk customers invite ops@importer.example --name "Dana Lee", which prints the link to send them. The headers reference lists what the app receives for a customer.