D.WTF

A sign-in button for your site.
No email.

Paste one snippet. Visitors sign in with a Passkey instead of Google, Apple, or a mailbox. The same install gives you cookieless analytics, push, and support.

What the snippet includes

Auth

Sign-in button

Passkey. No password, no email harvest, no OAuth profile. Users stay a key, you stay an app_id.

Analytics

Cookieless traffic

Pageviews without third-party tracking cookies. We do not store IP in business logic.

Push

Notify by user_id

Web Push to the person who already signed in. No phone number and no email campaign stack.

Support

In-app chat

Tickets and screenshots without asking for a name or email before the user can talk to you.

How it connects Open the console, create an app, set Brand to d.wtf, and paste the snippet. API api.d.wtf · script dev.d.wtf/dwtf.global.js · rank api.d.wtf/rank.

Not stored by default IP, email, and name are not stored by default. Passkey-first. Online identifiers may still be personal data, so consent remains the customer’s legal call.

Public browser delivery The browser client is served publicly from dev.d.wtf/dwtf.global.js (alias sdk.an.one). The self-serve console lives at dev.d.wtf.

Why two names Same product, not two services. d.wtf is a blunt protest against cookie walls, tracking banners, and consent theater. an.one is the same button in a calmer voice for teams who prefer restraint. We are not trying to confuse anyone. This is not a claim that cookie banners are not needed — consent remains your legal call.