Comment by mpetrovich

5 hours ago

I suspect they ask for email first in order to determine whether to log you in via SSO vs. require a password.

As someone who's built just that, can confirm. If users have SSO configured, or a Passkey, or any other policies apply, you first need to identify the account to be able to determine which options to offer - maybe they don't even have a password in the first place, so displaying the field would cause confusion. As a side effect, this also conveniently allows to check for blocked accounts.