CommerceHook

Signing in

There are no passwords here. You get in either by clicking a link we email you, or with a passkey that your device unlocks using your fingerprint, face or PIN.

Most people start with the emailed link and add a passkey later, once they are tired of waiting for email.

Getting in by email

Type your email address on the sign-in page and we will send you a link. Click it, press the button on the page it opens, and you are in.

The link lasts 15 minutes and works once. If you have never used CommerceHook before, that same link creates your account, so there is nothing separate to sign up for.

That button is there for a reason worth explaining. Corporate mail security, Microsoft Defender and the like, opens every link in a message to check it before you get to it. A link that signs you in the moment it is opened gets used up by the scanner, and you arrive to be told your link has expired when you only just received it. A scanner will follow a link. It will not press a button.

One deliberate quirk: the page says the same thing whether or not the address has an account. That stops anyone using the sign-in form to work out who does.

Using a passkey

A passkey lives on your phone, your laptop or in your password manager, and it unlocks with whatever you already use to unlock that device. It saves you waiting for an email on the machines you use every day.

To add one, sign in, then go to Settings and Passkeys. Give it a name you will still recognise in six months, something like “work laptop”, and follow your browser’s prompt. Add as many as you like.

To use one, click the email box on the sign-in page. If your browser has a passkey saved it offers it to you there, and confirming is the whole process.

To remove one, Settings, then Passkeys, then Remove.

If your browser does not do passkeys, you will never see any of this. The page stays an ordinary email form.

You cannot lock yourself out

A passkey is a shortcut, never the only key, and email always works. So:

  • Delete your last passkey if you want to. Your account carries on.
  • Lose your laptop and you have lost nothing but the passkey that was on it. Nobody can use it anywhere else, because the secret half never left that machine.
  • New computer? Sign in by email and add a passkey to it. There is no recovery process to sit through.

Signing out means everywhere

A session lasts seven days. Pressing Sign out ends it early, on every device you were signed in on rather than only the one you pressed the button on: your phone, your laptop and a browser you forgot about all land on the sign-in page. It is the shape a sign-out has to take here, and it is also the useful one when a laptop goes missing, because signing out anywhere signs it out too.

Keys for scripts are separate

The API, the CLI and MCP clients do not sign in as you. They use an API key you create in Settings and send with each request, or an app you connected in Settings. Signing out does not affect either, and neither does adding or removing passkeys. Revoke a key or a connected app from Settings when you want it gone. The API documentation covers how they work.

A few things worth knowing

  • Your browser ties a passkey to app.commercehook.app, so it will not work on a convincing fake of our sign-in page. That is the best reason to use one.
  • We store only the public half of a passkey. By itself it cannot sign anyone in, here or anywhere else.
  • Every sign-in prompt expires after five minutes, and each one works once.