Authentication
Authentication is split by trust boundary.
- Browser identity is validated by the Web service using configured issuer, client, redirect, TLS, and service Secret capabilities.
- Direct-IDE clients obtain a short-lived runtime credential through the local login socket; Managed runtime renewal is bounded and coordinated.
- Brokered clients receive a non-renewable projected credential with an absolute lifetime.
- OAuth and runtime authentication artifacts are stored as owner-bound Managed secrets. Public records retain safe identity and exact version provenance.
The Client bootstrap contains only Deployment identity, Trusted-runtime origin, and TLS trust. Tokens, client secrets, passwords, caches, credential file paths, and live handles never enter shared configuration or public protocol types.
Replacement is an owner transaction. Session and Datastore reference evidence blocks removal while a persisted authority still depends on a version. Unknown or unavailable reference inspection fails closed.