Development identity boundary

One login. Explicit entry everywhere.

This surface reports the non-production proof truthfully. It does not offer sign-in until the issuer, two exact origins, two distinct clients, and an approved server-side session store are all ready.

Three separate decisions

Authentication is not authorization.

01

Recognition

Auth0 may prove one issuer subject. Email and profile claims are not stable identity keys.

02

Membership

A recognised subject receives no application session until an explicit active membership exists.

03

Local session

Each relying party owns a separate host-only session. Application cookies are never shared across domains.

Exact origins only

Two relying parties, two local sessions.

Stable proof origins are deliberately absent until the implementation preview is ready for owner review. Wildcard Vercel callbacks are rejected.