Split Signup With Proof
Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
components/auth-login-card.tsxnpx hoverlab add auth-login-card
Or over MCP, from your editor's agent — no account needed.
Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.
Start a page with this section — add more, order them, and leave with the page source.
Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.
'use client'
/**
* <AuthLoginCard> — a centred email/password sign-in card.
*
* The password field's reveal toggle is a real <button> with an aria-label
* that changes with state, not an icon swapped inside the input. A reveal
* control that screen readers announce as "button" and nothing else is the
* single most common accessibility defect in sign-in forms.
*
* `autoComplete` values matter more here than anywhere else in an app:
* `username` and `current-password` are what tell a password manager this
* is a login rather than a registration, and getting them wrong is why
* saved credentials silently stop filling.
*/
import * as React from 'react'
import { Eye, EyeOff, Loader2, Github, Chrome } from 'lucide-react'
export interface AuthLoginCardProps {
heading?: string
subheading?: string
/** Reject to surface the error message. */
onSubmit?: (values: { email: string; password: string }) => Promise<void>
onSocial?: (provider: 'github' | 'google') => void
signupHref?: string
forgotHref?: string
className?: string
}
export function AuthLoginCard({
heading = 'Welcome back',
subheading = 'Sign in to pick up where you left off.',
onSubmit,
onSocial,
signupHref = '/signup',
forgotHref = '/forgot-password',
className = '',
}: AuthLoginCardProps) {
// Per-instance ids. A literal id in a reusable component is a
// collision waiting for the second copy on the page — and a <label>
// then resolves to whichever input rendered first.
const uid = React.useId()
const [email, setEmail] = React.useState('')
const [password, setPassword] = React.useState('')
const [visible, setVisible] = React.useState(false)
const [busy, setBusy] = React.useState(false)
const [error, setError] = React.useState<string | null>(null)
async function handleSubmit(event: React.FormEvent) {
event.preventDefault()
if (busy) return
setBusy(true)
setError(null)
try {
await onSubmit?.({ email, password })
} catch {
// Deliberately vague: naming which half was wrong tells an attacker
// whether the address exists.
setError('That email and password combination did not work.')
} finally {
setBusy(false)
}
}
return (
<div className={`flex min-h-96 w-full items-center justify-center p-6 ${className}`}>
<div className="w-full max-w-sm rounded-2xl border border-border/60 bg-card/80 p-7 shadow-sm backdrop-blur">
<div className="text-center">
<h1 className="text-2xl font-bold tracking-tight">{heading}</h1>
{subheading ? (
<p className="mt-1.5 text-sm text-muted-foreground">{subheading}</p>
) : null}
</div>
{/* Social first — most returning users came in that way. */}
<div className="mt-6 grid grid-cols-2 gap-3">
<button
type="button"
onClick={() => onSocial?.('github')}
className="inline-flex items-center justify-center gap-2 rounded-xl border border-border/60 bg-background px-3 py-2 text-sm font-medium transition-colors hover:bg-muted"
>
<Github aria-hidden className="h-4 w-4" />
GitHub
</button>
<button
type="button"
onClick={() => onSocial?.('google')}
className="inline-flex items-center justify-center gap-2 rounded-xl border border-border/60 bg-background px-3 py-2 text-sm font-medium transition-colors hover:bg-muted"
>
<Chrome aria-hidden className="h-4 w-4" />
Google
</button>
</div>
<div className="my-6 flex items-center gap-3">
<span aria-hidden className="h-px flex-1 bg-border/60" />
<span className="text-xs text-muted-foreground">or continue with email</span>
<span aria-hidden className="h-px flex-1 bg-border/60" />
</div>
<form onSubmit={handleSubmit} className="space-y-4">
<div>
<label htmlFor={`${uid}-login-email`} className="mb-1.5 block text-sm font-medium">
Email
</label>
<input
id={`${uid}-login-email`}
type="email"
required
autoComplete="username"
value={email}
onChange={(e) => setEmail(e.target.value)}
placeholder="you@company.com"
className="w-full rounded-xl border border-border/60 bg-background px-3.5 py-2.5 text-sm outline-none transition-shadow placeholder:text-muted-foreground focus-visible:ring-2 focus-visible:ring-primary"
/>
</div>
<div>
<div className="mb-1.5 flex items-baseline justify-between">
<label htmlFor={`${uid}-login-password`} className="block text-sm font-medium">
Password
</label>
<a
href={forgotHref}
className="text-xs font-medium text-muted-foreground transition-colors hover:text-foreground"
>
Forgot?
</a>
</div>
<div className="relative">
<input
id={`${uid}-login-password`}
type={visible ? 'text' : 'password'}
required
autoComplete="current-password"
value={password}
onChange={(e) => setPassword(e.target.value)}
placeholder="••••••••"
className="w-full rounded-xl border border-border/60 bg-background px-3.5 py-2.5 pe-11 text-sm outline-none transition-shadow placeholder:text-muted-foreground focus-visible:ring-2 focus-visible:ring-primary"
/>
<button
type="button"
onClick={() => setVisible((v) => !v)}
aria-label={visible ? 'Hide password' : 'Show password'}
aria-pressed={visible}
className="absolute end-1.5 top-1/2 -translate-y-1/2 rounded-lg p-2 text-muted-foreground transition-colors hover:bg-muted hover:text-foreground"
>
{visible ? (
<EyeOff aria-hidden className="h-4 w-4" />
) : (
<Eye aria-hidden className="h-4 w-4" />
)}
</button>
</div>
</div>
{/* Reserved space, so an error does not shove the button down. */}
<p aria-live="polite" className="min-h-5 text-sm text-destructive">
{error}
</p>
<button
type="submit"
disabled={busy}
className="inline-flex w-full items-center justify-center gap-2 rounded-xl bg-primary px-4 py-2.5 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90 disabled:opacity-60"
>
{busy ? <Loader2 aria-hidden className="h-4 w-4 animate-spin motion-reduce:[animation-duration:1.6s]" /> : null}
{busy ? 'Signing in' : 'Sign in'}
</button>
</form>
<p className="mt-6 text-center text-sm text-muted-foreground">
New here?{' '}
<a href={signupHref} className="font-semibold text-foreground hover:underline">
Create an account
</a>
</p>
</div>
</div>
)
}
bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.Drop it at components/auth-login-card.tsx and import it where you need the section:
import { AuthLoginCard } from '@/components/auth-login-card'4 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.
Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.
| Prop | Type | Default |
|---|---|---|
heading | string | 'Welcome back' |
subheading | string | 'Sign in to pick up where you left off.' |
onSubmitReject to surface the error message. | (values: { email: string; password: string }) => Promise<void> | — |
onSocial | (provider: 'github' | 'google') => void | — |
signupHref | string | '/signup' |
forgotHref | string | '/forgot-password' |
className | string | '' |
The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.
This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.
<!--
Email & Social Login Card — markup from the Hoverlab catalog.
This is the block rendered once to HTML and wrapped as a component
file. It is not a port of the React source: the Tailwind classes carry
the design, which is the part that took the work, and they are the same
in every framework.
This block is interactive in React and the handlers are NOT here.
Buttons, toggles and menus render in their initial state and do
nothing until you wire them up.
-->
<div class="flex min-h-96 w-full items-center justify-center p-6 ">
<div class="w-full max-w-sm rounded-2xl border border-border/60 bg-card/80 p-7 shadow-sm backdrop-blur">
<div class="text-center">
<h1 class="text-2xl font-bold tracking-tight">Welcome back</h1>
<p class="mt-1.5 text-sm text-muted-foreground">Sign in to pick up where you left off.</p>
</div>
<div class="mt-6 grid grid-cols-2 gap-3">
<button type="button" class="inline-flex items-center justify-center gap-2 rounded-xl border border-border/60 bg-background px-3 py-2 text-sm font-medium transition-colors hover:bg-muted"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-github h-4 w-4" aria-hidden="true"><path d="M15 22v-4a4.8 4.8 0 0 0-1-3.5c3 0 6-2 6-5.5.08-1.25-.27-2.48-1-3.5.28-1.15.28-2.35 0-3.5 0 0-1 0-3 1.5-2.64-.5-5.36-.5-8 0C6 2 5 2 5 2c-.3 1.15-.3 2.35 0 3.5A5.403 5.403 0 0 0 4 9c0 3.5 3 5.5 6 5.5-.39.49-.68 1.05-.85 1.65-.17.6-.22 1.23-.15 1.85v4"></path><path d="M9 18c-4.51 2-5-2-7-2"></path></svg>GitHub</button>
<button type="button" class="inline-flex items-center justify-center gap-2 rounded-xl border border-border/60 bg-background px-3 py-2 text-sm font-medium transition-colors hover:bg-muted"><svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-chrome h-4 w-4" aria-hidden="true"><circle cx="12" cy="12" r="10"></circle><circle cx="12" cy="12" r="4"></circle><line x1="21.17" x2="12" y1="8" y2="8"></line><line x1="3.95" x2="8.54" y1="6.06" y2="14"></line><line x1="10.88" x2="15.46" y1="21.94" y2="14"></line></svg>Google</button>
</div>
<div class="my-6 flex items-center gap-3">
<span aria-hidden="true" class="h-px flex-1 bg-border/60"></span>
<span class="text-xs text-muted-foreground">or continue with email</span>
<span aria-hidden="true" class="h-px flex-1 bg-border/60"></span>
</div>
<form class="space-y-4">
<div>
<label for="_R_0_-login-email" class="mb-1.5 block text-sm font-medium">Email</label>
<input id="_R_0_-login-email" type="email" required="" autoComplete="username" placeholder="you@company.com" class="w-full rounded-xl border border-border/60 bg-background px-3.5 py-2.5 text-sm outline-none transition-shadow placeholder:text-muted-foreground focus-visible:ring-2 focus-visible:ring-primary" value="" />
</div>
<div>
<div class="mb-1.5 flex items-baseline justify-between">
<label for="_R_0_-login-password" class="block text-sm font-medium">Password</label>
<a href="/forgot-password" class="text-xs font-medium text-muted-foreground transition-colors hover:text-foreground">Forgot?</a>
</div>
<div class="relative">
<input id="_R_0_-login-password" type="password" required="" autoComplete="current-password" placeholder="••••••••" class="w-full rounded-xl border border-border/60 bg-background px-3.5 py-2.5 pe-11 text-sm outline-none transition-shadow placeholder:text-muted-foreground focus-visible:ring-2 focus-visible:ring-primary" value="" />
<button type="button" aria-label="Show password" aria-pressed="false" class="absolute end-1.5 top-1/2 -translate-y-1/2 rounded-lg p-2 text-muted-foreground transition-colors hover:bg-muted hover:text-foreground">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-eye h-4 w-4" aria-hidden="true">
<path d="M2.062 12.348a1 1 0 0 1 0-.696 10.75 10.75 0 0 1 19.876 0 1 1 0 0 1 0 .696 10.75 10.75 0 0 1-19.876 0"></path>
<circle cx="12" cy="12" r="3"></circle>
</svg>
</button>
</div>
</div>
<p aria-live="polite" class="min-h-5 text-sm text-destructive"></p>
<button type="submit" class="inline-flex w-full items-center justify-center gap-2 rounded-xl bg-primary px-4 py-2.5 text-sm font-semibold text-primary-foreground transition-colors hover:bg-primary/90 disabled:opacity-60">Sign in</button>
</form>
<p class="mt-6 text-center text-sm text-muted-foreground">New here? <a href="/signup" class="font-semibold text-foreground hover:underline">Create an account</a></p>
</div>
</div>
What each framework gets across the whole catalog — effects convert properly; this rung is markup.
The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.
Want the whole screen instead of this one section? Open a page and copy it entire.
All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.
Browse AuthenticationCopying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.
Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.
Six-box OTP entry that handles paste, backspace, arrow keys and iOS SMS autofill — the parts hand-rolled versions always miss.
Reset-link request with a sent state worded to avoid leaking whether an account exists.
Set-a-new-password form with a four-step strength meter, confirm matching and errors announced rather than only coloured.
Authenticator-code prompt with a backup-code escape hatch and an opt-in trusted-device checkbox that is off by default.
Email first, then whatever that domain uses. The password field is absent rather than disabled when SSO is enforced, the button names the company it redirects to, and a personal address is a normal answer instead of an error.
Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.
What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.