Accounts and credentials
Sudomimus distinguishes account identity, sign-in credentials, and verified email ownership. These concepts apply to Connect, OIDC, and native direct-issue.
| Concept | What it represents |
|---|---|
| Account | The person and their profile. One account can have several sign-in methods and verified email addresses. |
| Sign-in credential | One credential the account can use, such as an email OTP login, passkey, Steam identity, OAuth identity, or enterprise federation identity. |
| Verified email ownership | An email address the account has proved it owns. At most one verified email is primary. |
Why they are separate
Section titled “Why they are separate”A credential proves how this person can sign in. Verified email ownership establishes which email this person owns. Those are related, but they are not the same fact.
For example:
- An email-OTP registration enables email-OTP sign-in and verifies email ownership.
- A Google, GitHub, or Discord login can establish verified email ownership without enrolling email OTP as a login method.
- A Steam-only account can sign in without owning any verified email.
- Removing a login method does not, by itself, remove the account’s verified email ownership.
This separation lets the platform evaluate login methods, email-based access rules, and shared profile data independently.
What applications see
Section titled “What applications see”Applications identify a signed-in user by the purpose-scoped sector subject in their tokens. They fetch any permitted identity claims from UserInfo.