Email & Social Login Card
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.
components/auth-magic-link-form.tsxnpx hoverlab add auth-magic-link-form
Or over MCP, from your editor's agent — no account needed.
Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.
Start a page with this section — add more, order them, and leave with the page source.
One address, one link, no password to forget or reuse. The link works once and expires in fifteen minutes, which is stated here rather than discovered when it fails.
Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.
'use client'
/**
* <AuthMagicLinkForm> — Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.
*
* A one-field form has an unusual layout problem: there is almost nothing
* to arrange, so everything rests on what the copy commits to. The obvious
* wrong answer is a bare email field and a button, which leaves the reader
* guessing whether a link or a code is coming, whether it expires, and
* whether the old password still works.
*
* So the hint carries the contract — one use, fifteen minutes — and it is
* under the field rather than in the success message. A constraint revealed
* after submission is a constraint the reader meets as a failure.
*
* The accessibility decision worth pointing at is that hint's wiring. The
* label is associated with `htmlFor`/`id` rather than by wrapping the input,
* which is what lets the hint sit outside the label and still be announced,
* through `aria-describedby`. Wrap the input in the label instead and the
* hint either gets swallowed into the accessible name or is never read.
*
* The live region is in the DOM from the first paint and empty. A
* `role="status"` element created at the moment it receives text is
* routinely never announced, because the assistive technology never saw it
* become live — and on this form that region is the entire result, since
* nothing else on screen changes when the link is sent.
*
* The demo defaults to `idle`. With no `onSubmit` passed it resolves
* immediately and shows the success state; throw from it to see the error
* path, which is where a real implementation reports an unknown address.
*/
import * as React from 'react'
export interface AuthMagicLinkFormProps {
heading?: string
intro?: string
submitLabel?: string
/** Called with the collected values. Resolve to accept, throw to reject. */
onSubmit?: (values: Record<string, string>) => Promise<void> | void
className?: string
}
type Status = 'idle' | 'pending' | 'done' | 'error'
/*
A typed array rather than `as const`. With `as const` the entries have
different shapes - some carry a hint, some do not - so `field.hint` is a
type error on the members that lack it, and the `'hint' in field` dance
needed to work around that is worse than declaring the field optional once.
*/
interface AuthMagicLinkFormField {
name: string
label: string
type: string
hint?: string
}
const FIELDS: AuthMagicLinkFormField[] = [
{ name: "email", label: "Email", type: "email", hint: "The link lands here and works once. It expires after 15 minutes." },
]
export function AuthMagicLinkForm({
heading = "Sign in without a password",
intro = "One address, one link, no password to forget or reuse. The link works once and expires in fifteen minutes, which is stated here rather than discovered when it fails.",
submitLabel = "Email me a link",
onSubmit,
className,
}: AuthMagicLinkFormProps) {
/*
Per-instance prefix for every id this block emits.
The literals these replaced were a latent duplicate the moment the
block appeared twice on one document, and `aria-labelledby` on a
duplicated id resolves to the first match -- so the second copy was
labelled by the first copy's heading. Client component, so `useId` is
the right tool.
*/
const uid = React.useId()
const [status, setStatus] = React.useState<Status>('idle')
const [message, setMessage] = React.useState('')
async function handleSubmit(event: React.FormEvent<HTMLFormElement>) {
event.preventDefault()
const data = new FormData(event.currentTarget)
const values = Object.fromEntries(
FIELDS.map((field) => [field.name, String(data.get(field.name) ?? '')]),
)
setStatus('pending')
try {
await onSubmit?.(values)
setStatus('done')
setMessage('Thanks — that came through.')
} catch (error) {
setStatus('error')
setMessage(error instanceof Error ? error.message : 'That did not go through.')
}
}
return (
<section
aria-labelledby={`${uid}-auth-magic-link-form-heading`}
className={`w-full bg-background px-6 py-16 ${className ?? ''}`}
>
<div className="mx-auto max-w-md rounded-xl border border-border bg-card p-8 shadow-sm">
<h2
id={`${uid}-auth-magic-link-form-heading`}
className="text-xl font-semibold tracking-tight text-card-foreground"
>
{heading}
</h2>
<p className="mt-2 text-sm text-muted-foreground">{intro}</p>
<form onSubmit={handleSubmit} className="mt-6 space-y-4">
{FIELDS.map((field) => (
<div key={field.name}>
{/*
htmlFor / id rather than a wrapping label, so the hint can
sit outside the label and still be announced — that is what
aria-describedby is for.
*/}
<label
htmlFor={`${uid}-auth-magic-link-form-${field.name}`}
className="block text-sm font-medium text-foreground"
>
{field.label}
</label>
<input
id={`${uid}-auth-magic-link-form-${field.name}`}
name={field.name}
type={field.type}
required
aria-describedby={field.hint ? `${uid}-auth-magic-link-form-${field.name}-hint` : undefined}
className="mt-1.5 w-full rounded-md border border-input bg-background px-3 py-2 text-sm text-foreground placeholder:text-muted-foreground focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring"
/>
{field.hint ? (
<p
id={`${uid}-auth-magic-link-form-${field.name}-hint`}
className="mt-1 text-xs text-muted-foreground"
>
{field.hint}
</p>
) : null}
</div>
))}
<button
type="submit"
disabled={status === 'pending'}
className="w-full rounded-md bg-primary px-4 py-2 text-sm font-medium text-primary-foreground transition-opacity hover:opacity-90 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring disabled:opacity-60"
>
{status === 'pending' ? 'Working…' : submitLabel}
</button>
{/*
The live region is always in the DOM and starts empty. A region
mounted at the moment it gets text is frequently not announced —
the assistive tech never saw it become live.
*/}
<p
role="status"
aria-live="polite"
className={`min-h-5 text-sm ${
status === 'error' ? 'text-destructive' : 'text-muted-foreground'
}`}
>
{message}
</p>
</form>
</div>
</section>
)
}
bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.Drop it at components/auth-magic-link-form.tsx and import it where you need the section:
import { AuthMagicLinkForm } from '@/components/auth-magic-link-form'2 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.
Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.
| Prop | Type | Default |
|---|---|---|
heading | string | "Sign in without a password" |
intro | string | — |
submitLabel | string | "Email me a link" |
onSubmitCalled with the collected values. Resolve to accept, throw to reject. | (values: Record<string, string>) => Promise<void> | void | — |
className | string | — |
The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.
This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.
<!--
Magic Link Sign In — markup from the Hoverlab catalog.
This is the block rendered once to HTML and wrapped as a component
file. It is not a port of the React source: the Tailwind classes carry
the design, which is the part that took the work, and they are the same
in every framework.
This block is interactive in React and the handlers are NOT here.
Buttons, toggles and menus render in their initial state and do
nothing until you wire them up.
-->
<section aria-labelledby="_R_0_-auth-magic-link-form-heading" class="w-full bg-background px-6 py-16 ">
<div class="mx-auto max-w-md rounded-xl border border-border bg-card p-8 shadow-sm">
<h2 id="_R_0_-auth-magic-link-form-heading" class="text-xl font-semibold tracking-tight text-card-foreground">Sign in without a password</h2>
<p class="mt-2 text-sm text-muted-foreground">One address, one link, no password to forget or reuse. The link works once and expires in fifteen minutes, which is stated here rather than discovered when it fails.</p>
<form class="mt-6 space-y-4">
<div>
<label for="_R_0_-auth-magic-link-form-email" class="block text-sm font-medium text-foreground">Email</label>
<input id="_R_0_-auth-magic-link-form-email" type="email" required="" aria-describedby="_R_0_-auth-magic-link-form-email-hint" class="mt-1.5 w-full rounded-md border border-input bg-background px-3 py-2 text-sm text-foreground placeholder:text-muted-foreground focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring" name="email" />
<p id="_R_0_-auth-magic-link-form-email-hint" class="mt-1 text-xs text-muted-foreground">The link lands here and works once. It expires after 15 minutes.</p>
</div>
<button type="submit" class="w-full rounded-md bg-primary px-4 py-2 text-sm font-medium text-primary-foreground transition-opacity hover:opacity-90 focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-ring disabled:opacity-60">Email me a link</button>
<p role="status" aria-live="polite" class="min-h-5 text-sm text-muted-foreground"></p>
</form>
</div>
</section>
What each framework gets across the whole catalog — effects convert properly; this rung is markup.
The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.
Want the whole screen instead of this one section? Open a page and copy it entire.
All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.
Browse AuthenticationCopying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.
Six-box OTP entry that handles paste, backspace, arrow keys and iOS SMS autofill — the parts hand-rolled versions always miss.
Reset-link request with a sent state worded to avoid leaking whether an account exists.
Set-a-new-password form with a four-step strength meter, confirm matching and errors announced rather than only coloured.
Authenticator-code prompt with a backup-code escape hatch and an opt-in trusted-device checkbox that is off by default.
Email first, then whatever that domain uses. The password field is absent rather than disabled when SSO is enforced, the button names the company it redirects to, and a personal address is a normal answer instead of an error.
What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.