SCENARIO

How SSO login through administrative oversight covers both convenience and security

Every login path converges on a single verification point.

  • Password sign-up, OIDC SSO, external IdP federation, and CLI device-flow all converge on session verification
  • After login, self-service features like persona management, organization invites, and repo access grants are easy to use
  • Bots and services get short-lived credentials through tokenhub
  • The admin API is the single place overseeing actors, tenants, and permissions across the board

Each node is tinted by the service it belongs to — click one for detail, drag to pan, scroll to zoom.