FiveGaits
AuthenticationSign in
  1. Sign in

Sign in

Select a provider to start your session.
Section: Authentication
Unauthenticated

Session actions

Global sign-in and session lifecycle actions.

Access path

Authentication, tenant selection, and role checks are evaluated separately.
1. Sign in with an enabled provider.
2. Confirm the active tenant before entering Admin or module workspaces.
3. Role and tenant permissions determine which actions are available after entry.

Operator trust checkpoint

Current sign-in posture before any tenant-scoped work opens.
Identity source: No trusted session
Tenant context: Tenant selection required
Membership: No active tenant membership
Downstream authorization: 0 capability marker(s); route actions remain independently checked
Safety posture: provider status, tenant choice, persona assignment, and RBAC are separate gates; this page does not grant tenant authority.

Auth providers

Enabled authentication providers for this environment.
Magic link
Email-based sign-in without passwords (stub).
Status: Disabled
Set EQUICORE_MAGIC_LINK=1 to enable magic-link sign-in.
Settings required: auth.magic.enabled, auth.email.mode
Missing env: EQUICORE_EMAIL_PROVIDER, EQUICORE_EMAIL_OUTBOX_DIR
Ask a sysadmin to enable this provider.
Docs: docs/auth/auth-spine.md
OIDC (Azure-ready)
OIDC SSO provider. Configure runtime env vars and enable settings before use.
Status: Configured
Docs: docs/auth/auth-roadmap.md