Email & Social Login Card
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
Email, OAuth, magic link, OTP and two-factor screens.
Auth is the screen with the highest abandonment and the least room for cleverness. What matters is boring: the password field has a reveal toggle, the email field has `autocomplete="email"` so the browser fills it, errors say which field failed, and the OAuth buttons are above the form rather than below it. All of that is wired here.
Centred sign-in card with social providers, a password reveal toggle and the autoComplete values password managers actually need.
Registration form beside a testimonial panel, with live password rules and a proof column that drops rather than stacks on mobile.
Six-box OTP entry that handles paste, backspace, arrow keys and iOS SMS autofill — the parts hand-rolled versions always miss.
Reset-link request with a sent state worded to avoid leaking whether an account exists.
Set-a-new-password form with a four-step strength meter, confirm matching and errors announced rather than only coloured.
Authenticator-code prompt with a backup-code escape hatch and an opt-in trusted-device checkbox that is off by default.
Email first, then whatever that domain uses. The password field is absent rather than disabled when SSO is enforced, the button names the company it redirects to, and a personal address is a normal answer instead of an error.
Passwordless sign-in that says what will land in the inbox and how long it lasts, before the address is typed.
What SSO actually covers, written for the person who has to configure it rather than the person who asked for it.
A full auth page that deliberately contains almost nothing but the form — no nav, no marketing, nothing competing with the one job.
The signup form with the proof under it rather than above it — the person who arrived here has already decided, and scrolling past testimonials is friction applied to the wrong reader.
Password reset, plus the magic link beside it — the moment after a password has failed is when somebody is most willing to stop using one.
The second factor with its fallback on the same screen, because a 2FA prompt with no recovery route is a lockout screen wearing a security screen.
A domain field for the employee who signs in daily, and the capability detail below the fold for the IT reviewer who reads it once.
The end of the forgot-password flow, shipped with the state it reaches more than any other screen: a focused error summary linking to each field, beside a strength meter that is a real <meter>.
Floating labels, filled and outlined fields, focus rings.
Multi-step wizards, checklists, tours and welcome screens.
Profile, preferences, team, security and danger zones.
Support requests, sales enquiries, split map-and-form layouts.
Stat rows, chart cards, activity feeds and admin shells.
Sortable grids, bulk selection, filters, pagination and row actions.