Auth components
16 Auth components for React, shadcn, Vue 3, Laravel Blade and HTML + Alpine.js: AuthLayout, DesktopLoginScreen, Device pairing, ForgotPasswordForm, IdleLock, InviteAccept, LockScreen, LoginForm, OAuthButtons, OAuthConsent, RegisterForm, ResetPasswordForm, SessionExpired, SignInFlow, TwoFactorChallenge, VerifyOtpForm.
- AuthLayoutPage shell for sign-in and sign-up screens: a centred card or a split layout with a brand panel, a heading, and a footer slot.
- DesktopLoginScreenA desktop OS sign-in screen. Wallpaper, a clock with a greeting, and a card with the mark and the Nasaq LoginForm, plus optional power buttons.
- Device pairingApprove a device by code with its claims, IP and platform; show an OAuth device-code with a big copyable code and link; and hand a browser sign-in to a native app.
- ForgotPasswordFormRequest a password reset link by email, then a Check your inbox state with a resend countdown and a change-email link; en and ar built in.
- IdleLockLocks the app after a period of inactivity: a Still there countdown dialog first, then your LockScreen over the inert app.
- InviteAcceptThe public accept-invitation page. It covers a valid invitation with accept and decline or sign in first, an expired one, one sent to another account, one already used and one that was cancelled.
- LockScreenOS-style lock screen over a wallpaper with a clock. Unlock by PIN keypad, password with an optional authenticator code, or biometrics, with a lockout after wrong tries and a quiet-mode gate.
- LoginFormPresentational sign-in form with email and password, magic link, remember me, provider buttons, passkey and a dev-only shortcut, built-in en and ar strings, linked errors and focus on the first invalid field.
- OAuthButtonsProvider sign-in buttons for Google, GitHub, Apple and Microsoft with their official logos, stacked, in a grid or icon-only, with per-provider loading.
- OAuthConsentAuthorization screen for a third-party app: app identity, signed-in account, requested scopes with sensitive badges, Allow and Deny, and the redirect host.
- RegisterFormPresentational sign-up form with name, email, password with strength meter, confirmation, terms consent and provider buttons; en and ar built in.
- ResetPasswordFormChoose a new password with a confirmation field, strength meter and optional policy checklist, then a Password changed or Link expired screen; en and ar built in.
- SessionExpiredRe-authentication form for a session that ended: the same person, a password (and code) or a passkey away, with switch account and sign out.
- SignInFlowIdentifier-first sign-in: the email and the providers first, then the step your backend picks for that address (password, one-time code, sign-in link, SSO, sign-up or blocked), with two-factor and forgot password in place.
- TwoFactorChallengeSecond-factor step at sign-in: authenticator code or recovery code, trust this device, and a passkey alternative; en and ar built in.
- VerifyOtpFormVerify an emailed or texted one-time code with auto-submit on the last digit, wrong-code clear and refocus, a masked destination and a resend countdown.
InstallPrompt
A PWA install dialog with a hook for the browser's install event and an iPhone walkthrough, plus a per-device push opt-in that reuses the notification permission prompt and lists subscribed devices.
AuthLayout
Page shell for sign-in and sign-up screens: a centred card or a split layout with a brand panel, a heading, and a footer slot.