Email & Social Login Card
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
Six-box OTP entry that handles paste, backspace, arrow keys and iOS SMS autofill — the parts hand-rolled versions always miss.
components/auth-otp-verify.tsxnpx hoverlab add auth-otp-verify
Or over MCP, from your editor's agent — no account needed.
Free to read, copy and install, for personal and non-commercial projects. Shipping it in client work or a paid product needs Pro ($79 once). The source lands in your repo and stops being ours — no attribution, nothing to upgrade.
Start a page with this section — add more, order them, and leave with the page source.
We sent a 6-digit code to you@company.com
Did not get it?
0 of 6 digits entered
Rendered live in your current theme — this is the same component whose source is below, not a screenshot of it.
'use client'
/**
* <AuthOtpVerify> — a six-box one-time-code input.
*
* The fiddly parts, all of which are why this is a block and not three
* lines of JSX:
*
* - Paste. Users paste the whole code from an email or SMS. Splitting a
* pasted string across the boxes is handled in `onPaste`, because
* without it the paste lands entirely in box one.
* - Backspace on an empty box moves focus back and clears the previous
* one, which is what every native implementation does.
* - Arrow keys move between boxes.
* - `inputMode="numeric"` and `autoComplete="one-time-code"` between them
* get the numeric keypad on mobile and let iOS autofill the code from
* the Messages app.
*
* The boxes are six inputs rather than one masked field because that is
* what users expect to see; the cost is all of the above.
*/
import * as React from 'react'
import { Loader2, ShieldCheck } from 'lucide-react'
export interface AuthOtpVerifyProps {
length?: number
heading?: string
/** Where the code went — shown so the user can catch a wrong address. */
destination?: string
onComplete?: (code: string) => Promise<void>
onResend?: () => void
className?: string
}
export function AuthOtpVerify({
length = 6,
heading = 'Check your email',
destination = 'you@company.com',
onComplete,
onResend,
className = '',
}: AuthOtpVerifyProps) {
const [digits, setDigits] = React.useState<string[]>(() => Array(length).fill(''))
const [busy, setBusy] = React.useState(false)
const [error, setError] = React.useState<string | null>(null)
const refs = React.useRef<Array<HTMLInputElement | null>>([])
const code = digits.join('')
function focusBox(index: number) {
refs.current[Math.max(0, Math.min(length - 1, index))]?.focus()
}
async function submit(value: string) {
setBusy(true)
setError(null)
try {
await onComplete?.(value)
} catch {
setError('That code is not right. Check it and try again.')
setDigits(Array(length).fill(''))
focusBox(0)
} finally {
setBusy(false)
}
}
function setDigit(index: number, value: string) {
const next = [...digits]
next[index] = value
setDigits(next)
if (value && index < length - 1) focusBox(index + 1)
const joined = next.join('')
if (joined.length === length && !joined.includes('')) void submit(joined)
}
function handleChange(index: number, raw: string) {
// Keep only the last digit typed: typing into a filled box should
// replace it, not be ignored because maxLength is already reached.
const digit = raw.replace(/\D/g, '').slice(-1)
setDigit(index, digit)
}
function handleKeyDown(index: number, event: React.KeyboardEvent<HTMLInputElement>) {
if (event.key === 'Backspace' && !digits[index] && index > 0) {
event.preventDefault()
const next = [...digits]
next[index - 1] = ''
setDigits(next)
focusBox(index - 1)
} else if (event.key === 'ArrowLeft') {
event.preventDefault()
focusBox(index - 1)
} else if (event.key === 'ArrowRight') {
event.preventDefault()
focusBox(index + 1)
}
}
function handlePaste(event: React.ClipboardEvent) {
event.preventDefault()
const pasted = event.clipboardData.getData('text').replace(/\D/g, '').slice(0, length)
if (!pasted) return
const next = Array(length).fill('')
for (let i = 0; i < pasted.length; i += 1) next[i] = pasted[i]
setDigits(next)
focusBox(pasted.length)
if (pasted.length === length) void submit(pasted)
}
return (
<div className={`flex min-h-96 w-full items-center justify-center p-6 ${className}`}>
<div className="w-full max-w-sm rounded-2xl border border-border/60 bg-card/80 p-7 text-center shadow-sm backdrop-blur">
<div className="mx-auto mb-4 inline-flex h-11 w-11 items-center justify-center rounded-xl bg-primary/15 text-primary">
<ShieldCheck className="h-5 w-5" />
</div>
<h1 className="text-2xl font-bold tracking-tight">{heading}</h1>
<p className="mt-1.5 text-sm text-muted-foreground">
We sent a {length}-digit code to{' '}
<span className="font-medium text-foreground">{destination}</span>
</p>
<div
role="group"
aria-label={`${length}-digit verification code`}
className="mt-7 flex justify-center gap-2"
onPaste={handlePaste}
>
{digits.map((digit, i) => (
<input
key={i}
ref={(el) => {
refs.current[i] = el
}}
type="text"
inputMode="numeric"
autoComplete={i === 0 ? 'one-time-code' : 'off'}
aria-label={`Digit ${i + 1}`}
maxLength={1}
disabled={busy}
value={digit}
onChange={(e) => handleChange(i, e.target.value)}
onKeyDown={(e) => handleKeyDown(i, e)}
onFocus={(e) => e.target.select()}
className="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60"
/>
))}
</div>
<p aria-live="polite" className="mt-4 min-h-5 text-sm">
{busy ? (
<span className="inline-flex items-center gap-1.5 text-muted-foreground">
<Loader2 aria-hidden className="h-4 w-4 animate-spin motion-reduce:[animation-duration:1.6s]" />
Verifying
</span>
) : null}
{error ? <span className="text-destructive">{error}</span> : null}
</p>
<p className="mt-2 text-sm text-muted-foreground">
Did not get it?{' '}
<button
type="button"
onClick={onResend}
className="font-semibold text-foreground hover:underline"
>
Send another
</button>
</p>
<p className="sr-only" aria-live="polite">
{code.length} of {length} digits entered
</p>
</div>
</div>
)
}
bg-card, text-muted-foreground) — it inherits your theme instead of overriding it.Drop it at components/auth-otp-verify.tsx and import it where you need the section:
import { AuthOtpVerify } from '@/components/auth-otp-verify'3 of this block’s props are simple enough to drive from here. Change them and the block below re-renders — it is the same component whose source is above, not a mock of it. Everything else it accepts is in the table underneath.
Read out of the component’s own type and signature, so this cannot drift from the source below. Every prop has a default — the component renders standalone before you pass it anything.
| Prop | Type | Default |
|---|---|---|
length | number | 6 |
heading | string | 'Check your email' |
destinationWhere the code went — shown so the user can catch a wrong address. | string | 'you@company.com' |
onComplete | (code: string) => Promise<void> | — |
onResend | () => void | — |
className | string | '' |
The same block rendered once to markup, wrapped as a file your framework compiles. Tailwind classes are framework-agnostic, so the design transfers intact — the behaviour does not.
This block is interactive. The markup below is its initial state with the event handlers stripped — you will need to re-wire the behaviour in your framework.
<!--
One-Time Code Input — markup from the Hoverlab catalog.
This is the block rendered once to HTML and wrapped as a component
file. It is not a port of the React source: the Tailwind classes carry
the design, which is the part that took the work, and they are the same
in every framework.
This block is interactive in React and the handlers are NOT here.
Buttons, toggles and menus render in their initial state and do
nothing until you wire them up.
-->
<div class="flex min-h-96 w-full items-center justify-center p-6 ">
<div class="w-full max-w-sm rounded-2xl border border-border/60 bg-card/80 p-7 text-center shadow-sm backdrop-blur">
<div class="mx-auto mb-4 inline-flex h-11 w-11 items-center justify-center rounded-xl bg-primary/15 text-primary">
<svg xmlns="http://www.w3.org/2000/svg" width="24" height="24" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-shield-check h-5 w-5" aria-hidden="true">
<path d="M20 13c0 5-3.5 7.5-7.66 8.95a1 1 0 0 1-.67-.01C7.5 20.5 4 18 4 13V6a1 1 0 0 1 1-1c2 0 4.5-1.2 6.24-2.72a1.17 1.17 0 0 1 1.52 0C14.51 3.81 17 5 19 5a1 1 0 0 1 1 1z"></path>
<path d="m9 12 2 2 4-4"></path>
</svg>
</div>
<h1 class="text-2xl font-bold tracking-tight">Check your email</h1>
<p class="mt-1.5 text-sm text-muted-foreground">We sent a 6-digit code to <span class="font-medium text-foreground">you@company.com</span></p>
<div role="group" aria-label="6-digit verification code" class="mt-7 flex justify-center gap-2">
<input type="text" inputMode="numeric" autoComplete="one-time-code" aria-label="Digit 1" maxLength="1" class="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60" value="" />
<input type="text" inputMode="numeric" autoComplete="off" aria-label="Digit 2" maxLength="1" class="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60" value="" />
<input type="text" inputMode="numeric" autoComplete="off" aria-label="Digit 3" maxLength="1" class="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60" value="" />
<input type="text" inputMode="numeric" autoComplete="off" aria-label="Digit 4" maxLength="1" class="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60" value="" />
<input type="text" inputMode="numeric" autoComplete="off" aria-label="Digit 5" maxLength="1" class="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60" value="" />
<input type="text" inputMode="numeric" autoComplete="off" aria-label="Digit 6" maxLength="1" class="h-12 w-11 rounded-xl border border-border/60 bg-background text-center text-lg font-semibold outline-none transition-shadow focus-visible:ring-2 focus-visible:ring-primary disabled:opacity-60" value="" />
</div>
<p aria-live="polite" class="mt-4 min-h-5 text-sm"></p>
<p class="mt-2 text-sm text-muted-foreground">Did not get it? <button type="button" class="font-semibold text-foreground hover:underline">Send another</button></p>
<p class="sr-only" aria-live="polite">0 of 6 digits entered</p>
</div>
</div>
What each framework gets across the whole catalog — effects convert properly; this rung is markup.
The component, its props, the design tokens it expects and the command that installs it — as one prompt. Paste it into Claude, Cursor, v0 or ChatGPT and what they build around it will match the rest of the catalog instead of inventing its own system.
Want the whole screen instead of this one section? Open a page and copy it entire.
All of them free to read, copy and install — no account, no locked tiles, no watermarked preview. The whole catalog is open, and so are the API and the CLI.
Browse AuthenticationCopying the code is free. Putting it in client work or a paid product is what Pro is for — the licence, not the access.
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.
Reset-link request with a sent state worded to avoid leaking whether an account exists.
Set-a-new-password form with a four-step strength meter, confirm matching and errors announced rather than only coloured.
Authenticator-code prompt with a backup-code escape hatch and an opt-in trusted-device checkbox that is off by default.
Email first, then whatever that domain uses. The password field is absent rather than disabled when SSO is enforced, the button names the company it redirects to, and a personal address is a normal answer instead of an error.
Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.
What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.