Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Authentication

Authentication is split by trust boundary.

  • Browser identity is validated by the Web service using configured issuer, client, redirect, TLS, and service Secret capabilities.
  • Direct-IDE clients obtain a short-lived runtime credential through the local login socket; Managed runtime renewal is bounded and coordinated.
  • Brokered clients receive a non-renewable projected credential with an absolute lifetime.
  • OAuth and runtime authentication artifacts are stored as owner-bound Managed secrets. Public records retain safe identity and exact version provenance.

The Client bootstrap contains only Deployment identity, Trusted-runtime origin, and TLS trust. Tokens, client secrets, passwords, caches, credential file paths, and live handles never enter shared configuration or public protocol types.

Replacement is an owner transaction. Session and Datastore reference evidence blocks removal while a persisted authority still depends on a version. Unknown or unavailable reference inspection fails closed.