Yeetline

The ways to sign in

Every way in ends at the same place: a key on your device that signs a challenge. What differs is what unlocks that key.

A passphrase unlocks the keystore this device holds. Choose a long one; the sign-in screen scores it as you type and offers a random one. A passkey is the step after it: your device's own lock — a fingerprint, a face, a PIN — a security key such as a YubiKey, or a password manager such as Bitwarden. It never travels and it cannot be phished. It does not replace the passphrase, because the passphrase is what opens your keys; it is a second lock in front of the account, and an operator can require one. Google signs you in through Google's own page; your address is kept here with your account, to find it by. On a deployment Yeetline runs for an organization that has not set up a Google sign-in of its own, that page is Yeetline's own Google sign-in, and Google's consent screen names Yeetline: on the way back from it your browser passes through Yeetline's server, which trades Google's answer for its signed statement of who you are and hands that straight on to the deployment, which checks it itself. Yeetline's server keeps no record of it. A guest is one press: a throwaway account that lasts while the tab is open.

Two-factor codes, where the operator requires them, are asked for after any of these. A device you have not used before is enrolled the first time it signs in, and Settings → Devices lists every one.

Adding Google to an account you already have

You do not have to choose at the start. Settings → Your Google Account → Link your Google account sends you to Google's consent screen and binds what comes back to the account you are signed in as, so Continue with Google finds it from then on. Your password still works and still seals your keys: Google names the account on the way in, and holds nothing that can read a message.

One Google account signs in one username, and one username answers to one Google account. If either is already spoken for you are told so rather than quietly moved.

A linked Google account is a second factor. While your account holds no authenticator app and no passkey, signing in with Continue with Google is the second step after your device's keys, wherever this server asks for one: nothing more is asked, no code and no email. The session that links it can go on at once to add an authenticator app or a passkey, if you would rather be asked for one of those; from then on that is what is asked, however you sign in. A session that reopened on its own — Stay signed in — has not shown it, so changing your factors from there asks you to first: Continue with Google in that dialog goes through Google's sign-in and comes back to Settings, with nothing to sign out of (signing out of an account made with Google, with no passphrase of its own, would take its keys on this device with it). Unlinking removes the factor, and a staff session it opened is closed. So does an administrator's reset of your second factors, which leaves the Google account linked — it still signs you in — and no longer your second step: Your Google account under Two-Factor Authentication says so, and Use it again there takes you through Google's sign-in to the same Google account and makes it your second step again. Until then no code goes to its address as one either.

Unlink is there too, once there is something to fall back on. An account created through Google has no passphrase of its own — its keys are sealed under a secret the browser made, which no other device has — so Google is genuinely the way in, and unlinking would shut the door. For that account Settings → Your Passphrase says Set a passphrase instead of Change passphrase: choose one, the keys here are re-sealed under it, and Unlink is yours from then on. Google goes on signing you in either way.

The section is there only where this server has Google sign-in switched on, and never for a guest: that account lasts as long as the tab.

See Signing in and Your account.

Last changed 2026-10-06