Contract
Accounts
How Institute accounts are created, verified and protected, who administers them, and the rules for your app.
Creation
Section titled “Creation”Public sign-up is on. Anyone creates an account on the IdP’s login screen and verifies the email by link. The IdP administration can also create an account; the person then verifies the email and sets the password by link. The email counts as verified only once the link is opened. Having an account grants nothing in any app.
New account, zero permissions. Authentication grants nothing. See Identity and access.
Email verification is on whenever the IdP has SMTP. Public sign-up requires it: without SMTP the deploy fails and the realm stays closed.
- One email per account: two accounts never share an address (
duplicateEmailsAllowedisfalse). - People sign in with their username or their email.
email_verified: set only by the link (Claims).- Password recovery goes through the IdP; the old password stops working.
Passwords and attempts
Section titled “Passwords and attempts”| Rule | Value |
|---|---|
| Minimum length | 12 characters |
| Must differ from | the username and the email |
| Brute-force protection | after 30 failures, a growing wait, 1 minute at a time, up to 15 minutes |
| Permanent lockout | no; the wait is temporary |
| Remember me | off |
| Second factor (OTP) | optional for regular accounts; mandatory for administration |
Events
Section titled “Events”Login and admin events, with details, are kept for 30 days at the IdP. The trail of actions inside your app (who approved what) belongs to your app.
Administration
Section titled “Administration”- One service administrator, in an administrative account separate from their everyday one, with OTP.
- Support people have named administrative accounts, with OTP, that only view and manage the Institute’s users and read login events: they reset passwords, unlock accounts and end sessions. They never change the realm, the clients or an administrator.
- Automation (the deploy) uses its own restricted credential, never a person’s password or OTP.
- A regular person cannot register a client or gain a role by having an account.
Apps have no administrative credential and no admin API. A person who needs help with their account goes to the IdP support, not to your app’s admin screen.