Skip to content

Sign in and manage an organization

Private qualification reviewed 21 September 2026. Ophiolite now supports a configured OpenID Connect identity provider. This does not require every user to have corporate SSO. A provider may handle passwords, passkeys or social sign-in; password sign-in and TOTP authenticator enrollment/sign-in have been tested. Virtual passkey enrollment and fresh passwordless login are now qualified on the private HTTPS hostname. Physical-device acceptance remains separate.

Choose Continue with Ophiolite Account (the provider label may differ by deployment). Complete sign-in at the provider. The administrator must have linked your provider identity, or you must accept an organization invitation. Matching an email does not automatically link accounts or grant project access.

If sign-in fails, retry; if it still fails, ask your administrator to check your account mapping. An expired session requires sign-in again. Signing out ends the current Ophiolite session, not your provider session or other applications. A new Continue action may therefore sign you straight back in. The private pilot retains a provisioned device-credential fallback; enterprise SSO-only enforcement is not claimed.

In Settings, an owner can rename an organization; its ID and existing asset links stay unchanged. Recent administration events appear below. In Members, owners can add an existing provisioned account, promote/demote owners, or remove members. To hand over, promote another member first, then step down or leave. The last owner cannot be removed, even when multiple requests arrive together. Members may leave themselves but cannot administer other members.

Organization roles do not grant scientific data access. Removing membership does not revoke separate project grants. Use Project Access to review those grants. Administration activity is separate from scientific lineage and does not alter units, nulls, coordinates, provenance or exact revisions.

Tested against a real Keycloak provider on Linux and Mac Chrome, including unknown identities, callback rejection and last-owner protection. Private invitation links, local captured-email recovery and TOTP were additionally tested in Linux Chrome. Trusted HTTPS browser login and a server-rendered exact scientific read passed with a diagnostic DNS mapping. Real inbox recovery through Proton-to-Gmail is now qualified. Physical passkeys, multi-worker identity routing remains open. Mac Chrome normal DNS/TLS now passes. See the identity contract and availability.

An owner opens Members → Invite a colleague, enters the colleague’s verified provider email, and creates an invitation. When SMTP is configured, Workspace queues an email and shows submission status. The colleague can sign in or register through the configured provider and verify the invited email. See the full invitation and import workflow.

Links expire after two days, work once, and can be revoked before acceptance. If a link fails, check the provider’s verified email or ask for a replacement. Acceptance grants membership only. Grant project data access separately.

From the organization list, open Account security to view and revoke your browser sessions. Manage sign-in and recovery opens the provider’s account UI. An authenticator supplies a second sign-in code after the password when enrolled. Provider recovery requires configured email delivery; local test-mail capture does not establish delivery to real inboxes. Ask the administrator if recovery is absent.

Completed browser sessions now survive a gateway restart; an interrupted sign-in must be started again. Local sign-out and Sign out all browser sessions do not sign out the identity provider or revoke device credentials. With provider session checks configured, provider disable/logout is checked within a 15-second cache window on the next protected request. This does not erase data already downloaded.

Generated demo scopes are hidden by default. Show archived test scopes reveals them again without changing permissions or scientific revisions.