One touch — your fingerprint, face or device PIN. The credential never leaves your device and cannot be phished: your browser will only offer it to this exact origin.
or sign in with a password
Multi-factor is mandatory — there is no password-only path (§12). Credentials come from the secret store this service was deployed with; a development boot that generates its own prints them only when explicitly asked to. This page is served to anyone who can reach the port, so it does not say where to look for them. Your session token is held in memory only: it is never stored in a cookie or localStorage, so closing this tab ends the session.