Team sign-in and access control

Your team signs in with a passkey or an emailed code. You choose who opens each app.

Built on WebAuthn and Caddy

Plans: Every plan, including the free app

What you get

  • Sign-in with a passkey or an emailed code
  • An optional password for people who want one
  • Roles from owner to member, plus guests
  • Groups such as directors or site staff
  • Access set app by app
  • One removal that closes every app at once

How it works

Whisk runs sign-in for every app, so no app has its own login page, password store or reset flow to get wrong. People sign in with a passkey, built on the WebAuthn open standard, or with a six-digit code sent by email. Owners and admins who sign in without a passkey are asked to add one.

Every request passes through Caddy, the open-source web server, which checks who the person is and whether they may open that app. The app then receives the person's ID, email, roles and groups in request headers, and decides what each person can do inside it.

Owners and admins choose who opens each app: everyone in the business, named groups or named people. Removing a person takes them out of every app, group and agent token in one step. Customers use a separate customer sign-in and never join your team.

Example

An engineering firm runs a project tracker for all its staff and a fee approvals app for the directors group only. A new graduate gets an invitation, signs in with an emailed code on the first day and adds a passkey on their laptop. When they leave, one removal closes the tracker and everything else.

For your coding agent

whisk access show
whisk dev --as <email> --groups <group> --roles <role>

whisk access show lists who may open the app. whisk dev sends the same identity headers on a laptop, so role checks can be tested before a deploy. The headers are listed in the headers reference.

Read more

All features