Credentials are checked against a salted scrypt digest, sessions live in rotating refresh-token families with reuse detection, and every device that touches the account is recorded and revocable.
Scrypt-hashed credentials
Refresh-token reuse detection
Revocable per-device sessions
A wrong password and an unknown address fail identically. The API never confirms who has an account.
Sign in
Enter your institutional address and we will email you a secure sign-in link.
or sign in with a password
Trouble signing in? Contact your institution’s administrator.