Ask a small store owner where their support time goes and "where's my order?" is near the top. Ask their customers what they hate and it's making yet another account. So every store on HelloWorld CMS gets the same thing at /account: type your email, click the link we send, see your orders. No password, ever.

What the customer sees

An email field. Then a neutral "check your email" message. Then, from the link, their own orders — status, tracking, the address it shipped to. Sign out when you're done. That's the whole interface, and it's on every store automatically; there's nothing to enable per site.

The six rules underneath

Passwordless is only simpler for the customer if the rules underneath are strict. Ours:

  1. The link works once and expires in 15 minutes. Used links and old links are dead.
  2. We never store the token. The database holds only a one-way hash of it; the actual token exists only in the email. A stolen database can't be used to sign in.
  3. Every order is checked against the signed-in email. Knowing an order number gets you nothing — the order has to belong to you.
  4. The response is the same whether or not the email exists. You can't use the form to discover which emails have accounts.
  5. Requests are rate-limited, so the form can't be used to spray inboxes.
  6. A customer session is not an admin session. They're separate keys, and neither one grants the other. Being signed in as a customer gives exactly zero access to the store's admin, and the reverse.

Why it matters for a small brand

Every password you store is a liability you didn't want. Every reset flow is a sale that might not happen. A magic link removes both, and it turns out customers understand it instantly — they've been using it for years on other services without knowing the name.

The same /account address is where returning-customer features go next: saved addresses, reorders. The door is built; we add rooms behind it.