Toqen provides QR-based login, temporary access passes, and TOTP verification without storing user information. The goal is to create a simple, privacy-first alternative to email login and passwords.
It uses Cloudflare Turnstile for anti-bot protection and runs on an edge-first stack. I would appreciate feedback from the community on the architecture, security considerations, and potential pitfalls.