Sign In
Help Center / Frequently Asked Questions

Frequently Asked Questions

Instant answers to common questions about your identity, security, and services.

Our SSO service is an OpenID Connect (OIDC) and OAuth 2.0 compliant identity provider. With a single set of credentials or Passkey, you can securely access all connected platforms, services, and authorized partner applications without needing separate logins.
Navigate to the Account Recovery Page, enter your registered email address, and follow the link sent to your inbox. If your account experienced 5 consecutive failed login attempts, a 15-minute security cooldown is automatically enforced.
Passkeys replace passwords with cryptographic FIDO2 / WebAuthn public keys bound to your physical device (Touch ID, Face ID, Windows Hello, or YubiKey). In case your device is lost or inaccessible, your account generates 10 single-use emergency backup recovery codes and provides signed email magic login links for secure, self-service account restoration.
Access tokens expire every 15 minutes for maximum security. Rolling refresh tokens maintain your session for up to 7 days on active devices, rotating security tokens on each renewal with CSRF protection.
Yes! When you select a theme (Auto/System, Light, Dark) or language, the setting is preserved via domain cookies across all connected services in the ecosystem.
You can revoke authorized application access directly from your account settings, or request full account deletion by reaching out to our data protection team at [email protected].
For security, accounts require email confirmation before full session tokens are issued. If you see the auth.email_unverified dialog, click the inline Resend email button directly inside the dialog or visit the Email Verification Status page. Check both your Inbox and Spam folders. For protection against spam, verification emails enforce a 60-second cooldown per recipient.
In non-production environments, the SSO service automatically detects private RFC 1918 / RFC 3927 subnets (192.168.x.x, 10.x.x.x, 172.16-31.x.x, 169.254.x.x). Any redirect URI configured with localhost or 127.0.0.1 automatically rewrites to the incoming client host IP so your physical iPhone or Android device completes OAuth flows seamlessly without loopbacks. Furthermore, HSTS and CSP upgrade-insecure-requests are conditioned to production only, preventing mobile browsers from blocking plain HTTP testing on private network IPs.
To prevent authorization code leakage and broken state loops, direct user visits to /login or /register without a client_id automatically strip orphaned /auth/callback or /oidc/callback destinations. To initiate an authorized application handshake and receive an authorization code at your callback endpoint, always launch the flow with your registered client_id: /oidc/authorize?client_id=YOUR_CLIENT_ID&redirect_uri=...&response_type=code.
Yes! Our SSO identity provider supports FIDO2 WebAuthn Passkeys. Once enrolled in your Account Dashboard (under Security → Register Passkey), you can sign in instantly using biometric sensors on your device (Face ID, Touch ID, Windows Hello) or hardware tokens like YubiKeys without entering a password. Passkeys are phishing-resistant and cryptographically tied to the identity domain.
When logging in with Telegram, our server verifies the cryptographic HMAC-SHA256 signature generated by Telegram using the official bot token. Profile avatars are securely sandboxed under our Content Security Policy (allowing only authorized t.me endpoints). You can link or unlink your Telegram account anytime from Account Settings without affecting other login methods.
SSO client registration and OpenID Connect identity integration are 100% free forever for all developers with generous fair-use allocations (up to 5 applications, 10,000 monthly active users, and 120 req/min token rate limits). There are zero subscription fees, no credit cards required, and no surprise paywalls. If your production application outgrows the standard allocation, you can request a free quota extension anytime via our Help Center.
In single-page applications (React, Vue, games, video players), call sso.loginWithPopup() using our client SDK. This opens a centered modal window pointing to /oidc/authorize?display=popup. Upon sign-in, the SSO service redirects to /oidc/popup-callback which automatically emits a postMessage containing the authorization code to the parent window and closes itself without interrupting the user's ongoing session.

Still have questions?

Our support engineers are here to assist with identity and technical inquiries.