Identity and access
Sign-in and sessions
Passwords, passkeys, and how the apps share one account session.
Passwords
Passwords are at least 12 characters (up to 256). Change yours on your account page at https://id.dev.gov.vin under Password. Passwords are stored as salted scrypt hashes.
Passkeys
A passkey signs you in with your device (Touch ID, Windows Hello, a phone or a security key) instead of a password.
- On your account page, under Passkeys, add one and give it a name.
- Next time, choose Sign in with passkey on the sign-in page. You don't need to type your email.
Remove a passkey from the same list. Passkeys work alongside your password.
Sessions
Signing in at id.dev.gov.vin starts your account session, which lasts 7 days.
Cloud, Git, Chat, Knowledge, Mail and Admin each sign in through it: the first time you open one, it sends you to id.dev.gov.vin and back, then keeps its own tokens:
| Token | Lifetime | |
|---|---|---|
| Access token | 15 minutes | Sent with every request the app makes for you. |
| Refresh token | 30 days | Renews the access token. Each use replaces it with a new one. |
Each app stores its tokens in cookies on its own hostname only (HttpOnly, Secure, SameSite=Lax), so no other app, and none of your deployments, can read them.
Your organizations and roles travel in the access token, so a change to them reaches an app within 15 minutes.
Sign out
- Sign out in an app removes that app's tokens. Your account session continues, so other apps keep working and the next sign-in doesn't ask for your password.
- Sign out on your account page ends the account session.
Using another account
Sign out on your account page, then sign in with the other account. When you approve an agent, Use another account does this and brings you back to the approval.
Standards
id.dev.gov.vin is an OAuth 2.1 issuer for the platform's own apps: authorization code flow with PKCE (S256) only, ES256-signed JWT access tokens, single-use authorization codes and rotating refresh tokens. Its discovery document is at https://id.dev.gov.vin/.well-known/openid-configuration and its keys at https://id.dev.gov.vin/.well-known/jwks.json. Agents log in with the device authorization grant (Login and approval).
"Sign in with" for your own apps, using these accounts, is planned. Coming soon