| Specification | Current statement | State |
|---|---|---|
| WebAuthn / passkeys | In development. | In development |
| OAuth 2.0 with PKCE | In development. | In development |
| OpenID Connect | In development. | In development |
| Credential fallback | Password fallback policy is in development. | In development |
| Signature family | Post-quantum token signing is in development; production details are not published. | In development |
Authenticator
In development. Runtime, custody and policy boundaries remain open.
Protocols
Token life
| Specification | Published value | State |
|---|---|---|
| Access token | 60 seconds | Confirmed |
| Session | 24 hours | Confirmed |
| Refresh token | 30 days; rotation behavior is in development. | In development |
| Refresh family cap | 90 days from first issuance. | Confirmed |
| Replay grace | 10 seconds; idempotent retry. | Confirmed |
Feature gates
- Token subject handling
- Exact construction is not published.
- In development
- Hardware-key support
- Compatibility scope is not published.
- In development
- Trusted-contact recovery
- In development.
- In development
- Cross-device enrollment
- In development.
- In development
- Multi-tenant organisation
- Scope taxonomy remains open.
- In development
- Scoped API keys
- Taxonomy and limits remain open.
- In development
- DPoP / SAML
- Research only.
- Research
- MFA beyond passkeys
- Supported factors and policy boundary remain open.
- Research
- Directory synchronisation
- Not offered.
- Not offered
Credential roles
| Specification | Authenticator | Security Key | State |
|---|---|---|---|
| Product category | Application sign-in and policy scope — in development | Physical credential — in development | In development |
| Relationship | May accept hardware credentials; compatibility scope unresolved | May act as a credential; physical specification unresolved | Research |