Come login

Sign-in is handled inside the verified first-party app. This profile documents the supported methods, the password reset flow and the 2FA configuration that is live on the 2026-08-17 snapshot.

A clean mobile flow showing a sign-in screen and a 2FA code prompt
Sign-in is one tap on the verified app. Web login is not exposed on this profile by design.

Why login lives inside the app

Come does not expose a web sign-in on this profile. Login is handled inside the verified first-party app because credentials must be entered over the partner's TLS endpoint and the session must bind to the device attestation token. Web sign-in would mean shipping the credential form to a third-party browser context, breaking both attestation and the 2FA challenge. The first-party app is the only supported sign-in surface.

Sign-in methods on the snapshot

  • Mobile number + OTP - the default. A 6-digit OTP is sent to the registered mobile number; the OTP expires in 5 minutes.
  • Username + password - supported, but the password is set inside the app. There is no public password-recovery web form on this profile.
  • 2FA via authenticator app - optional. Once enabled, every login from a new device triggers a TOTP challenge.
  • Biometric unlock - supported on devices with a fingerprint sensor or face unlock. The biometric secret is stored in the device's secure enclave; Come never receives the biometric template.

Password reset and account recovery

If you have lost access to the registered mobile number, the in-app password reset flow falls back to the recovery e-mail address you set during registration. The e-mail address is verified by a one-time link valid for 30 minutes. If neither the mobile nor the e-mail is reachable, open a ticket with customer care from the e-mail address on file; the team will ask for the last successful login timestamp and the device model to confirm ownership before unlocking the account.

2FA configuration

2FA is configured inside the app under Settings → Security → Two-factor authentication. Scan the QR code with any TOTP authenticator (Google Authenticator, Aegis, Authy, 1Password). Once enabled, a new device sign-in requires the 6-digit TOTP code in addition to the OTP. The recovery codes are shown only once at setup - save them offline.

Frequently asked questions

I never set a password. How do I sign in?

If you registered with mobile-number-only, sign in with OTP. The password field is optional in that case.

What if the OTP never arrives?

Wait 60 seconds and request a new code. OTPs that have not been requested should be treated as suspicious; never share an OTP with anyone - Come staff will never ask for it.

Can I sign in on two devices at the same time?

Yes. Sessions on multiple devices are allowed. Each device session is independently attested and can be revoked from Settings → Security → Active sessions.

How do I delete my account?

Account deletion is documented on the delete account page. The request is processed within 7 working days.

Login only on the verified app

If a page or a chat asks you to enter your Come password outside the verified first-party app, treat it as a phishing attempt. The only supported login surface is the app itself.