Skip to content

Contract

Accounts

How Institute accounts are created, verified and protected, who administers them, and the rules for your app.

Public sign-up is on. Anyone creates an account on the IdP’s login screen and verifies the email by link. The IdP administration can also create an account; the person then verifies the email and sets the password by link. The email counts as verified only once the link is opened. Having an account grants nothing in any app.

Your app must

New account, zero permissions. Authentication grants nothing. See Identity and access.

Email verification is on whenever the IdP has SMTP. Public sign-up requires it: without SMTP the deploy fails and the realm stays closed.

  • One email per account: two accounts never share an address (duplicateEmailsAllowed is false).
  • People sign in with their username or their email.
  • email_verified: set only by the link (Claims).
  • Password recovery goes through the IdP; the old password stops working.
RuleValue
Minimum length12 characters
Must differ fromthe username and the email
Brute-force protectionafter 30 failures, a growing wait, 1 minute at a time, up to 15 minutes
Permanent lockoutno; the wait is temporary
Remember meoff
Second factor (OTP)optional for regular accounts; mandatory for administration

Login and admin events, with details, are kept for 30 days at the IdP. The trail of actions inside your app (who approved what) belongs to your app.

  • One service administrator, in an administrative account separate from their everyday one, with OTP.
  • Support people have named administrative accounts, with OTP, that only view and manage the Institute’s users and read login events: they reset passwords, unlock accounts and end sessions. They never change the realm, the clients or an administrator.
  • Automation (the deploy) uses its own restricted credential, never a person’s password or OTP.
  • A regular person cannot register a client or gain a role by having an account.

Apps have no administrative credential and no admin API. A person who needs help with their account goes to the IdP support, not to your app’s admin screen.