Customer sign-in

Let customers sign in to a portal, invited or open to sign-up.

Built on WebAuthn and Caddy

Plans: Every plan, including the free app

What you get

  • Sign-in with an emailed code or a passkey
  • Invite-only by default, or open to sign-up
  • Sign-in pages and emails in the app's name
  • One customer list per app, or shared by several apps
  • Invite, block and remove customers
  • Customers kept apart from your team and dashboard

How it works

You turn customer sign-in on with one line in the app's whisk.yaml. Customers sign in with an emailed code or a passkey, built on the WebAuthn open standard, on a page in the app's name. A customer account can never open your dashboard or the Whisk API.

A new portal is invite-only. An owner or admin invites customers from the dashboard, or the app invites them through Whisk's API as part of its own onboarding. An owner can open sign-up when anyone should be able to register.

Caddy, the open-source web server, checks every request, and the app reads the customer's ID and email from request headers. Blocking a customer takes effect on their next request. Your own staff keep their team sign-in.

Example

A freight forwarder gives each importer a portal to track shipments and download customs documents. The account manager invites each importer's contacts, who sign in with an emailed code the first time and a passkey after that. When a contact leaves the importer, the forwarder blocks them from the dashboard.

For your coding agent

customer_identity: app
routes:
  public: ["/", "/health"]

Invite a first customer with whisk customers invite ops@importer.example --name "Dana Lee", which prints the link to send them. The headers reference lists what the app receives for a customer.

All features