> ## Documentation Index
> Fetch the complete documentation index at: https://docs.p2hs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

> Configure authentication for a project without exposing credentials to the browser.

P2HS authentication includes passwordless magic-link flows, access and refresh tokens, sessions, TOTP, backup-code recovery, trusted devices, and WebAuthn/passkeys. Project authentication configuration is separate from platform account authentication.

## Security model

* authenticate users through the platform’s session and token contracts;
* keep authorization checks on the server;
* scope project operations to the workspace and project;
* use roles and permissions for project-specific access;
* never put provider or deployment credentials in generated browser code.

Use the dashboard and the project authentication configuration to manage application sign-in and authorization.

For sign-in and session problems, see [Authentication and forms troubleshooting](/content/support/troubleshooting/authentication-forms).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.