Skip to content

Authentication and workspaces

Status: MVP complete.

Users can register, verify email, sign in with a password, Google, or Facebook, use passkeys/2FA, and receive a personal workspace automatically. OAuth callbacks validate per-session state and store provider identities separately from the user. A verified provider email may link to an existing account. From Connected accounts settings, authenticated users can add, replace, or remove their Google and Facebook identities. Only configured providers and existing connections are shown, so unavailable integrations are not advertised. Social-only users must set a local password or retain another connected provider before removing their final provider. Social-only accounts can set a local password and enroll passkeys or 2FA from security settings.

Workspace owners and admins can invite users; roles are owner, admin, and member. Document queries and authenticated downloads require workspace membership. Email shares use separate signed, expiring download URLs.

Workspace URLs are slug-scoped and users can switch among their memberships. The hostname selects locale: .hu is Hungarian; .com uses English.