Skip to main content
P2HS authentication includes passwordless magic-link flows, access and refresh tokens, sessions, TOTP, backup-code recovery, trusted devices, and WebAuthn/passkeys. Project authentication configuration is separate from platform account authentication.

Security model

  • authenticate users through the platform’s session and token contracts;
  • keep authorization checks on the server;
  • scope project operations to the workspace and project;
  • use roles and permissions for project-specific access;
  • never put provider or deployment credentials in generated browser code.
See the API authentication reference for the public API header model.