[{"data":1,"prerenderedAt":498},["ShallowReactive",2],{"navigation":3,"\u002Fapps\u002Fidp":152,"\u002Fapps\u002Fidp-surround":493},[4,44,83,96,109],{"title":5,"path":6,"stem":7,"children":8,"icon":43},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,11,15,19,23,27,31,35,39],{"title":10,"path":6,"stem":7},"Introduction",{"title":12,"path":13,"stem":14},"Quick Start: Service Provider","\u002Fgetting-started\u002Fquickstart-sp","1.getting-started\u002F2.quickstart-sp",{"title":16,"path":17,"stem":18},"Quick Start: Identity Provider","\u002Fgetting-started\u002Fquickstart-idp","1.getting-started\u002F3.quickstart-idp",{"title":20,"path":21,"stem":22},"Quick Start: Agent","\u002Fgetting-started\u002Fquickstart-agent","1.getting-started\u002F4.quickstart-agent",{"title":24,"path":25,"stem":26},"Quick Start","\u002Fgetting-started\u002Finstallation","1.getting-started\u002F5.installation",{"title":28,"path":29,"stem":30},"How It Works","\u002Fgetting-started\u002Fhow-it-works","1.getting-started\u002F6.how-it-works",{"title":32,"path":33,"stem":34},"For Service Providers","\u002Fgetting-started\u002Ffor-service-providers","1.getting-started\u002F7.for-service-providers",{"title":36,"path":37,"stem":38},"CLI (apes & ape-shell)","\u002Fgetting-started\u002Fcli","1.getting-started\u002F8.cli",{"title":40,"path":41,"stem":42},"Free-IdP Hosting Guide","\u002Fgetting-started\u002Ffree-idp-hosting","1.getting-started\u002F9.free-idp-hosting",false,{"title":45,"path":46,"stem":47,"children":48,"icon":43},"Ecosystem","\u002Fecosystem","2.ecosystem\u002F1.index",[49,51,55,59,63,67,71,75,79],{"title":50,"path":46,"stem":47},"Overview",{"title":52,"path":53,"stem":54},"OpenApe Auth","\u002Fecosystem\u002Fauth","2.ecosystem\u002F2.auth",{"title":56,"path":57,"stem":58},"OpenApe Grants","\u002Fecosystem\u002Fgrants","2.ecosystem\u002F3.grants",{"title":60,"path":61,"stem":62},"nuxt-auth-sp","\u002Fecosystem\u002Fnuxt-auth-sp","2.ecosystem\u002F4.nuxt-auth-sp",{"title":64,"path":65,"stem":66},"escapes","\u002Fecosystem\u002Fescapes","2.ecosystem\u002F5.escapes",{"title":68,"path":69,"stem":70},"nuxt-auth-idp","\u002Fecosystem\u002Fnuxt-auth-idp","2.ecosystem\u002F6.nuxt-auth-idp",{"title":72,"path":73,"stem":74},"Multi-Tenant IdP","\u002Fecosystem\u002Fmulti-tenant-idp","2.ecosystem\u002F7.multi-tenant-idp",{"title":76,"path":77,"stem":78},"Agent Recipe","\u002Fecosystem\u002Fagent-recipe","2.ecosystem\u002F8.agent-recipe",{"title":80,"path":81,"stem":82},"Agent Catalog","\u002Fecosystem\u002Fagent-catalog","2.ecosystem\u002F9.agent-catalog",{"title":84,"icon":43,"path":85,"stem":86,"children":87,"page":43},"Security","\u002Fsecurity","3.security",[88,92],{"title":89,"path":90,"stem":91},"Compliance","\u002Fsecurity\u002Fcompliance","3.security\u002F1.compliance",{"title":93,"path":94,"stem":95},"Threat Model","\u002Fsecurity\u002Fthreat-model","3.security\u002F2.threat-model",{"title":97,"icon":43,"path":98,"stem":99,"children":100,"page":43},"Guides","\u002Fguides","4.guides",[101,105],{"title":102,"path":103,"stem":104},"Capabilities & Grants","\u002Fguides\u002Fcapabilities","4.guides\u002F1.capabilities",{"title":106,"path":107,"stem":108},"Delegation","\u002Fguides\u002Fdelegation","4.guides\u002F2.delegation",{"title":110,"path":111,"stem":112,"children":113,"icon":151},"Apps","\u002Fapps","5.apps\u002F01.index",[114,115,119,123,127,131,135,139,143,147],{"title":50,"path":111,"stem":112},{"title":116,"path":117,"stem":118},"OpenApe ID","\u002Fapps\u002Fidp","5.apps\u002F02.idp",{"title":120,"path":121,"stem":122},"Troop","\u002Fapps\u002Ftroop","5.apps\u002F03.troop",{"title":124,"path":125,"stem":126},"Chat","\u002Fapps\u002Fchat","5.apps\u002F04.chat",{"title":128,"path":129,"stem":130},"Tasks","\u002Fapps\u002Ftasks","5.apps\u002F05.tasks",{"title":132,"path":133,"stem":134},"Plans","\u002Fapps\u002Fplans","5.apps\u002F06.plans",{"title":136,"path":137,"stem":138},"Testrun","\u002Fapps\u002Ftestrun","5.apps\u002F07.testrun",{"title":140,"path":141,"stem":142},"Timetrack","\u002Fapps\u002Ftimetrack","5.apps\u002F08.timetrack",{"title":144,"path":145,"stem":146},"PR","\u002Fapps\u002Fpr","5.apps\u002F09.pr",{"title":148,"path":149,"stem":150},"CRM","\u002Fapps\u002Fcrm","5.apps\u002F10.crm","i-lucide-layout-grid",{"id":153,"title":116,"body":154,"description":486,"extension":487,"links":488,"meta":489,"navigation":490,"path":117,"seo":491,"stem":118,"__hash__":492},"docs\u002F5.apps\u002F02.idp.md",{"type":155,"value":156,"toc":453},"minimark",[157,164,169,172,177,185,191,195,198,203,207,210,215,219,222,227,231,234,238,241,246,250,257,262,266,277,282,286,300,305,309,312,316,323,328,332,335,340,344,351,356,360,370,375,379,382,386,391,396,400,403,408,412,415,420,424,427,430,436,441,445,448],[158,159,160],"note",{},[161,162,163],"p",{},"Every step below is captured from a live end-to-end run on the local stack — the screenshots refresh on each capture, so this guide cannot drift from the real product.",[165,166,168],"h2",{"id":167},"create-your-identity","Create your identity",[161,170,171],{},"Register a WebAuthn passkey — no password, ever. Your OpenApe ID becomes the DDISA authority for your identity: every Service Provider logs you in via DNS-discovered SSO without ever seeing a credential.",[173,174,176],"h3",{"id":175},"open-openape-id","Open OpenApe ID",[161,178,179,180,184],{},"The landing page asks for nothing but your email. Click ",[181,182,183],"strong",{},"Create account"," to start.",[161,186,187],{},[188,189],"img",{"alt":176,"src":190},"\u002Fguides\u002Fidp\u002Fcreate-identity\u002F01-landing.png",[173,192,194],{"id":193},"request-your-registration-link","Request your registration link",[161,196,197],{},"Enter your email — OpenApe ID sends you a one-time registration link.",[161,199,200],{},[188,201],{"alt":194,"src":202},"\u002Fguides\u002Fidp\u002Fcreate-identity\u002F02-request-link.png",[173,204,206],{"id":205},"register-your-passkey","Register your passkey",[161,208,209],{},"The link opens the passkey ceremony. Your device (Touch ID, Windows Hello, a security key) creates the credential — in this E2E run a virtual authenticator answers headlessly.",[161,211,212],{},[188,213],{"alt":206,"src":214},"\u002Fguides\u002Fidp\u002Fcreate-identity\u002F03-register-passkey.png",[173,216,218],{"id":217},"done-you-are-signed-in","Done — you are signed in",[161,220,221],{},"That's the whole sign-up: one passkey, no password to remember or leak.",[161,223,224],{},[188,225],{"alt":218,"src":226},"\u002Fguides\u002Fidp\u002Fcreate-identity\u002F04-registered.png",[165,228,230],{"id":229},"your-account-dashboard","Your account dashboard",[161,232,233],{},"Your dashboard is home base for your identity. Passkeys, SSH keys, agents, permissions, delegations and connected services each have their own page, so you go straight to the one you need.",[173,235,237],{"id":236},"open-your-dashboard","Open your dashboard",[161,239,240],{},"Once you're signed in, the dashboard brings together everything tied to your identity — passkeys, SSH keys, agents, permissions, delegations and connected services. Choose an area to open it.",[161,242,243],{},[188,244],{"alt":237,"src":245},"\u002Fguides\u002Fidp\u002Faccount-dashboard\u002F01-dashboard.png",[173,247,249],{"id":248},"manage-your-passkeys","Manage your passkeys",[161,251,252,253,256],{},"Open ",[181,254,255],{},"Passkeys"," to manage how you sign in — add a new device, or remove one you no longer use.",[161,258,259],{},[188,260],{"alt":249,"src":261},"\u002Fguides\u002Fidp\u002Faccount-dashboard\u002F02-passkeys.png",[173,263,265],{"id":264},"manage-your-ssh-keys","Manage your SSH keys",[161,267,268,271,272,276],{},[181,269,270],{},"SSH keys"," holds the public keys for ",[273,274,275],"em",{},"Sign in with SSH Key",". Paste a key to add it, or remove one you've retired.",[161,278,279],{},[188,280],{"alt":265,"src":281},"\u002Fguides\u002Fidp\u002Faccount-dashboard\u002F03-ssh-keys.png",[173,283,285],{"id":284},"review-connected-services","Review connected services",[161,287,288,291,292,295,296,299],{},[181,289,290],{},"Connected services"," lists the apps you've signed in to with your OpenApe ID. Revoke one and you'll be asked to approve it again next time. Apps acting for you at ",[273,293,294],{},"another"," service live under ",[181,297,298],{},"Delegations",".",[161,301,302],{},[188,303],{"alt":285,"src":304},"\u002Fguides\u002Fidp\u002Faccount-dashboard\u002F04-connected-services.png",[165,306,308],{"id":307},"recover-your-account-or-stop-an-attack-in-one-tap","Recover your account — or stop an attack in one tap",[161,310,311],{},"Lost every device with a passkey? Account recovery lets you enrol a new one after a waiting period — and because every recovery attempt is announced loudly on all your channels, an attacker can never run one quietly. This is the whole flow, from both sides.",[173,313,315],{"id":314},"start-a-recovery","Start a recovery",[161,317,318,319,322],{},"On the sign-in page choose ",[181,320,321],{},"Lost access?"," — no password reset, no support ticket. Recovery only ever grants permission to register a new passkey; it never signs anyone in by itself.",[161,324,325],{},[188,326],{"alt":315,"src":327},"\u002Fguides\u002Fidp\u002Faccount-recovery\u002F01-start-recovery.png",[173,329,331],{"id":330},"request-it-for-your-email","Request it for your email",[161,333,334],{},"Enter your account email. OpenApe ID answers the same way whether the address has an account or not, so nobody can use this form to probe for accounts. If it is yours, the waiting period starts now.",[161,336,337],{},[188,338],{"alt":331,"src":339},"\u002Fguides\u002Fidp\u002Faccount-recovery\u002F02-requested.png",[173,341,343],{"id":342},"every-channel-gets-the-warning","Every channel gets the warning",[161,345,346,347,350],{},"The warning goes out immediately: a push notification to every device you enabled notifications on, and a mail to every address that was ever linked to your account — even ones you replaced years ago. A single compromised mailbox cannot swallow the alarm. Each warning names the exact moment the recovery could complete and carries a one-tap ",[181,348,349],{},"Cancel recovery"," link that works without signing in.",[161,352,353],{},[188,354],{"alt":343,"src":355},"\u002Fguides\u002Fidp\u002Faccount-recovery\u002F03-warning-sent.png",[173,357,359],{"id":358},"cancel-it-in-one-tap","Cancel it in one tap",[161,361,362,363,365,366,369],{},"Didn't request it? Tap ",[181,364,349],{}," in any warning — or on your ",[181,367,368],{},"Recovery protection"," page, one click from the dashboard — and the attempt is dead for good. A cancelled recovery can never be completed, not even after its waiting period would have ended. Signing in with one of your existing passkeys cancels it automatically, too.",[161,371,372],{},[188,373],{"alt":359,"src":374},"\u002Fguides\u002Fidp\u002Faccount-recovery\u002F04-cancelled.png",[165,376,378],{"id":377},"vacation-mode-a-longer-shield-while-you-are-away","Vacation mode: a longer shield while you are away",[161,380,381],{},"The recovery waiting period adapts to how you use your account: 7 days while you are active, 72 hours once an account has been dormant for a month. Going off-grid? Vacation mode stretches the shield to up to 14 days so nobody can take over your account while you cannot react.",[173,383,385],{"id":384},"open-recovery-protection","Open Recovery protection",[161,387,252,388,390],{},[181,389,368],{}," from your dashboard. Vacation mode lives here, in your account settings — only you, signed in, can change it. There is no way to flip it from the outside.",[161,392,393],{},[188,394],{"alt":385,"src":395},"\u002Fguides\u002Fidp\u002Frecovery-vacation-mode\u002F01-settings.png",[173,397,399],{"id":398},"switch-on-vacation-mode","Switch on vacation mode",[161,401,402],{},"Switch it on and pick how long a recovery attempt has to wait — up to 14 days, which is also the hard maximum. While it is on, the vacation wait applies no matter how recently you signed in.",[161,404,405],{},[188,406],{"alt":399,"src":407},"\u002Fguides\u002Fidp\u002Frecovery-vacation-mode\u002F02-vacation-on.png",[173,409,411],{"id":410},"your-shield-is-set","Your shield is set",[161,413,414],{},"That's it. A recovery requested from now on is bound to the wait that applied at the moment of the request — switching vacation mode off later never shortens a deadline that is already running.",[161,416,417],{},[188,418],{"alt":411,"src":419},"\u002Fguides\u002Fidp\u002Frecovery-vacation-mode\u002F03-vacation-set.png",[165,421,423],{"id":422},"see-every-recovery-attempt-nothing-disappears","See every recovery attempt — nothing disappears",[161,425,426],{},"Every recovery attempt against your account is on permanent record: when it happened, where it came from, and how it ended. Attackers cannot probe quietly, and nobody — not even you — can scrub the record.",[173,428,385],{"id":429},"open-recovery-protection-1",[161,431,432,433,435],{},"The recovery history sits on your ",[181,434,368],{}," page, right under vacation mode — visible only to you while signed in.",[161,437,438],{},[188,439],{"alt":385,"src":440},"\u002Fguides\u002Fidp\u002Frecovery-history\u002F01-settings.png",[173,442,444],{"id":443},"review-every-attempt","Review every attempt",[161,446,447],{},"Each entry shows when the attempt was made, where it came from (IP address and browser, as far as known) and what became of it: still running — including the moment it could complete — finished, cancelled, or expired unused. Entries contain no links or codes an attacker could reuse, and they can neither be edited nor deleted: the cancelled attempt from the previous chapter stays on record forever.",[161,449,450],{},[188,451],{"alt":444,"src":452},"\u002Fguides\u002Fidp\u002Frecovery-history\u002F02-history.png",{"title":454,"searchDepth":455,"depth":456,"links":457},"",1,2,[458,465,471,477,482],{"id":167,"depth":456,"text":168,"children":459},[460,462,463,464],{"id":175,"depth":461,"text":176},3,{"id":193,"depth":461,"text":194},{"id":205,"depth":461,"text":206},{"id":217,"depth":461,"text":218},{"id":229,"depth":456,"text":230,"children":466},[467,468,469,470],{"id":236,"depth":461,"text":237},{"id":248,"depth":461,"text":249},{"id":264,"depth":461,"text":265},{"id":284,"depth":461,"text":285},{"id":307,"depth":456,"text":308,"children":472},[473,474,475,476],{"id":314,"depth":461,"text":315},{"id":330,"depth":461,"text":331},{"id":342,"depth":461,"text":343},{"id":358,"depth":461,"text":359},{"id":377,"depth":456,"text":378,"children":478},[479,480,481],{"id":384,"depth":461,"text":385},{"id":398,"depth":461,"text":399},{"id":410,"depth":461,"text":411},{"id":422,"depth":456,"text":423,"children":483},[484,485],{"id":429,"depth":461,"text":385},{"id":443,"depth":461,"text":444},"Register a WebAuthn passkey — no password, ever. Your OpenApe ID becomes the DDISA authority for your identity: every Service Provider logs you in via DNS-discovered SSO without ever seeing a…","md",null,{},true,{"title":116,"description":486},"AHGwqwmiWYyJEUoAk06-4j-l8xMFolKcHtNNYgb1EY8",[494,496],{"title":50,"path":111,"stem":112,"description":495,"children":-1},"Every OpenApe app, documented from a live end-to-end run: OpenApe ID, Troop, Chat, Tasks, Plans, Testrun, Timetrack, PR, CRM.",{"title":120,"path":121,"stem":122,"description":497,"children":-1},"Troop is a DDISA Service Provider: it discovers your IdP from your email domain via a DNS TXT record and redirects you there to authorize — no password, no per-app account.",1787307024961]