Sign-in you can see happening

No passwords over
the wire. Ever.

Scanning a Miirak QR is not sign-in. The approval you do on your phone is. Here's what happens in the ~2 seconds between the scan and being signed in.

01

Browser mints a challenge

The website creates a short-lived, single-use code and shows it as a QR. No account details, no token.

02

You scan with the app

The Miirak app on your (already-authenticated) phone reads the code and fetches the request details.

03

You see who's asking

The app shows the domain, IP, browser, and time. A phishing site would show the wrong domain here.

04

Approve with a fingerprint

Only your biometric can complete the approval. The browser is then signed in — the QR becomes unusable.

kariim.dev · 90s
Waiting for approval on your Miirak app…
Miirak · Approve sign-in
Approve sign-in?
Domainkariim.dev
IP address185.132.44.19
BrowserSafari · macOS
Timejust now
Approve with fingerprint
Why this beats a magic link

Not a shared secret

The QR contains no reusable token. Photographing it, forwarding it, or intercepting it in transit is useless without your phone.

Two devices, one approval

The device you're signing in on and the device that authorises the sign-in are different. That kills whole classes of phishing attack.

Sub-2-minute lifetime

Every challenge expires in 90 seconds and is single-use. There is no long-lived link to leak in an email or SMS.

Chained audit trail

Every approval and rejection is recorded with a chained hash so tampering after the fact would be detectable.