Separate service sessions
A sibling service cannot read or reuse another service’s host-only cookie.
Account security
SVCS First keeps one canonical identity while every service holds a separate host-only session.
No account or session details are exposed while signed out.
A sibling service cannot read or reuse another service’s host-only cookie.
One-time codes, S256 PKCE, state, and exact registered callbacks protect every handoff.
Party, workspace, resource, and capability access are rechecked for protected operations.
Actor tokens stay server-side and cannot outlive the validated session that created them.