Home / Sign in

Sign in to the Blackjack In reading account

Your Blackjack In account holds your reading preferences, the articles you have bookmarked and the format tracks you have followed. It is a reading account, not a payment account.

Sign-in cover image

What the account is, and what it is not

The Blackjack In account is a reading account. It is not a real-money rummy account, it does not hold a balance and it does not process payments. If you are looking for a real-money rummy account, the platform you choose is responsible for that account; the desk does not hold a balance on your behalf.

What the account does is hold your reading preferences, the articles you have bookmarked and the format tracks you have followed. The account is free, the reading is free, and the desk accepts no payment for any account-related feature.

How to sign in

Sign in with the email and password you used when you created the account. If you do not have an account, you can create one on the same page; the desk will not send you marketing email, will not share your email with any third party, and will not ask for any payment information at any point in the process.

Forgot your password

If you have forgotten your password, use the reset link below the sign-in form. The desk will send a reset link to the email on file; the link expires after one hour for safety. The desk will never ask for your password over email, on the phone or in a chat window.

Two-factor authentication

The desk recommends two-factor authentication for any account that holds reading preferences. The 2FA is a one-time code sent to the email on file; the desk does not currently support authenticator apps, but the email-based 2FA is sufficient for the limited data the account holds.

How the desk handles failed sign-in attempts

The desk locks the account after 5 failed sign-in attempts in a 15-minute window. The lock is released automatically after 15 minutes, or immediately after a successful password reset. The desk does not currently support a permanent lock; the lock is a temporary measure to slow down credential-stuffing attacks.

What the desk does not do: the desk does not email the reader a list of failed sign-in attempts; the desk does not lock the account on the first failed attempt; the desk does not require a CAPTCHA on the sign-in form. The desk treats the sign-in form as a low-risk surface; the lock is a backstop, not a primary defence.

How the desk handles session management

The desk uses a session cookie that expires after 30 days of inactivity. The cookie is signed with a server-side secret; the cookie is HttpOnly and SameSite=Lax. The desk does not currently support a "remember me" checkbox; the session is renewed automatically when the reader is active.

What the desk does not do: the desk does not track the reader across devices; the session is per-device. The desk does not currently support a single sign-on (SSO) provider; the sign-in is email-and-password only. The desk does not currently support a passkey or a hardware token; the password is the only authentication factor beyond the email-based 2FA.

How the desk handles account recovery

Account recovery is done through the password reset flow. The reader enters the email address on the account; the desk sends a reset link to the email address; the reader clicks the link and sets a new password. The reset link expires after 1 hour. The desk does not currently support a phone-based recovery; the email is the only recovery channel.

What the desk does not do: the desk does not ask for the password over email, on the phone or in a chat window. The desk does not currently support a security question or a backup email address. The desk does not currently support a recovery code; the email is the only recovery channel.

Play now