Skip to content

Accounts and credentials

View as Markdown

Sudomimus distinguishes account identity, sign-in credentials, and verified email ownership. These concepts apply to Connect, OIDC, and native direct-issue.

Concept What it represents
Account The person and their profile. One account can have several sign-in methods and verified email addresses.
Sign-in credential One credential the account can use, such as an email OTP login, passkey, Steam identity, OAuth identity, or enterprise federation identity.
Verified email ownership An email address the account has proved it owns. At most one verified email is primary.

A credential proves how this person can sign in. Verified email ownership establishes which email this person owns. Those are related, but they are not the same fact.

For example:

  • An email-OTP registration enables email-OTP sign-in and verifies email ownership.
  • A Google, GitHub, or Discord login can establish verified email ownership without enrolling email OTP as a login method.
  • A Steam-only account can sign in without owning any verified email.
  • Removing a login method does not, by itself, remove the account’s verified email ownership.

This separation lets the platform evaluate login methods, email-based access rules, and shared profile data independently.

Applications identify a signed-in user by the purpose-scoped sector subject in their tokens. They fetch any permitted identity claims from UserInfo.