Skip to content
Droptape

01Sign in

One link, fifteen minutes.

Droptape has no passwords. Give us an address, we mail you a link, and clicking it signs you in for 30 days. There is nothing to forget, and nothing in our database worth stealing — the link and the session are both stored hashed.

The bot check is not configured on this deployment, so sign-in requests are limited by rate only. Nothing else about signing in changes.

Signing up? Same form. If the address has no account yet, following the link creates one. That is also why the confirmation below is worded the same either way: we will not tell a stranger which of your addresses are registered here.

The session cookie is HTTP-only, same-site and expires after 30 days of not being used. Signing out deletes it server-side, not just in your browser.