Recognition
Auth0 may prove one issuer subject. Email and profile claims are not stable identity keys.
Development identity boundary
This surface reports the non-production proof truthfully. It does not offer sign-in until the issuer, two exact origins, two distinct clients, and an approved server-side session store are all ready.
Three separate decisions
Auth0 may prove one issuer subject. Email and profile claims are not stable identity keys.
A recognised subject receives no application session until an explicit active membership exists.
Each relying party owns a separate host-only session. Application cookies are never shared across domains.
Exact origins only
Stable proof origins are deliberately absent until the implementation preview is ready for owner review. Wildcard Vercel callbacks are rejected.