SISuperintelligenceDocs

Search docs

Search every page of the documentation.

Identity and access

Sign-in and sessions

Passwords, passkeys, and how the apps share one account session.

Passwords

Passwords are at least 12 characters (up to 256). Change yours on your account page at https://id.gov.vin under Password. Passwords are stored as salted scrypt hashes.

Passkeys

A passkey signs you in with your device (Touch ID, Windows Hello, a phone or a security key) instead of a password.

  1. On your account page, under Passkeys, add one and give it a name.
  2. Next time, choose Sign in with passkey on the sign-in page. You don't need to type your email.

Remove a passkey from the same list. Passkeys work alongside your password.

Sessions

Signing in at id.gov.vin starts your account session, which lasts 7 days.

Cloud, Git, Chat, Knowledge, Mail and Admin each sign in through it: the first time you open one, it sends you to id.gov.vin and back, then keeps its own tokens:

TokenLifetime
Access token15 minutesSent with every request the app makes for you.
Refresh token30 daysRenews the access token. Each use replaces it with a new one.

Each app stores its tokens in cookies on its own hostname only (HttpOnly, Secure, SameSite=Lax), so no other app, and none of your deployments, can read them.

Your organizations and roles travel in the access token, so a change to them reaches an app within 15 minutes.

Sign out

  • Sign out in an app removes that app's tokens. Your account session continues, so other apps keep working and the next sign-in doesn't ask for your password.
  • Sign out on your account page ends the account session.

Using another account

Sign out on your account page, then sign in with the other account. When you approve an agent, Use another account does this and brings you back to the approval.

Standards

id.gov.vin is an OAuth 2.1 issuer: authorization code flow with PKCE (S256) only, ES256-signed JWT access tokens, single-use authorization codes and rotating refresh tokens. The platform's own apps use /authorize and /token; your apps (Sign in with) and MCP clients (MCP server) use /oauth/*, described by https://id.gov.vin/.well-known/openid-configuration (also at /.well-known/oauth-authorization-server). Keys are at https://id.gov.vin/.well-known/jwks.json. Agents log in with the device authorization grant (Login and approval).

Connected apps

Your account page lists the apps and MCP clients you signed in to under Connected apps. Remove ends that app's access: its refresh tokens stop working at once, and its current access token within the hour.

Sign-ins in the audit log

Sign-ins and failed sign-ins (password or passkey) are recorded in the audit log of every organization you belong to, as account.sign_in and account.sign_in_failed.

Rate limits

Sign-in pages and token endpoints are rate limited per IP address: past the limit, requests get 429 with Retry-After for a few minutes (Limits).