Tap to sync
Vitamins, water, anything daily. Open the panel — the 💊 button in the filter row above the calendar, or here — to rename, pause, add or delete; it also shows the last 30 days of ticks. The history is kept even when the chips are hidden.
The Trackers view (📈 in the header) is the full picture: month grid, streak, percentage, a dated note per day, and trackers of their own with no event (stretching, anything you only log).
Use this on the phone if another device (or Google) shows shifted times: the times you see here become the ones every device keeps.
Version —. If another device shows something newer, this one is still running the old copy — reopen the app (swipe it away and tap the icon again) or press Reload.
Checking the sign-in state…
The access code is the whole sign-in: it is asked once per device, and iOS offers to save it in iCloud Keychain — after that Face ID fills it on this very screen. “Lock this device” forgets it and asks again (with Face ID).
Why Face ID never appeared here. Cloudflare Access guards the site, and the login page for this app serves only the one-time PIN form — no Google button, so there was no password field for iOS to fill. Compare with spaces/journal, where Google sits on the login page.
One setting brings Google here (checked 22 Sep 2026). Both apps are on the same Cloudflare Zero Trust team (calendar-dah-pages.cloudflareaccess.com): spaces' login page already offers “Sign in with: Google”, the calendar's offers only the PIN. So the Google identity provider already exists for this account and no Google Cloud work is needed — only this application has to be allowed to use it: Zero Trust → Access controls → Applications → calendar-dah.pages.dev → Configure → Authentication → pick All identity providers (or just Google) → Save. The login page then gets a Google button, and iOS fills Google's password by Face ID from iCloud Keychain.
Ask less often. On that same Configure screen set Session Duration to 1 month: both apps are on 24 hours today, which is why the email code (and now Google) is asked for daily.
The alternative — take Access out of the way. Zero Trust → Access controls → Applications → the calendar app → Add a policy → Action Bypass, Include Everyone (or delete the application): the page then loads straight into the calendar and only the code is asked for. Check first that ACCESS_CODE is set in Pages → Settings → Variables and secrets — after the bypass it is the only thing standing between the world and your calendar, and /api/gh refuses to touch GitHub without it.
What still protects the files. The Pages worker serves a short allow-list (app, icons, service worker, plus toddler.html and toddler-events.json for the 🧸 view — those two are the public listings the nanny pages also show, not family data) and answers 404 to everything else. Without that, a public site would also hand out calendar-data.json, calendar.ics, journal-summary.json and repository files such as _deploy.py, which carries a GitHub token.
Google Cloud Console → APIs & Services → Credentials → OAuth client ID (Web) — add https://calendar-dah.pages.dev to Authorized JavaScript origins. The calendar ID is in Google Calendar → that calendar → Settings → Integrate calendar. The time zone is only the default for events that carry none of their own.
Some are repeating events:
How would you like to change it?
This calendar is protected. Enter the access code to continue.
Saved in iCloud Keychain once — after that Face ID fills it. This device stays unlocked.
Every failed Google request and every failed save on this device: the event, the HTTP status and the raw answer. Repeats of the same failure are counted (×N) instead of listed over and over. Only the last 50 are kept, and only on this device.
What about the days after?
Choose where to move its events: