Auth control plane
DiyaOS
Passwordless identity
Bootstrap
Create the first OS admin.
Login
Passkey, FIDO key, or OTP fallback.
Verify
OTP step-up and periodic checks.
Recover
No-password recovery entry point.
Profile
Security profile and access posture.
Posture
Recovery readiness and backup path.
Replace
Lost-device credential replacement.
Notify
Security event preferences.
Invite
Accept tenant or admin invitations.
Request
Ask for platform or tenant access.
Authorize
Approve app access and redirect.
Device
Register passkeys and security keys.
Scope
Choose OS, platform, tenant, or app context.
Session
Review current session and trusted device state.
Logout
End this browser session.
DiyaOS Auth
Logout
End the local browser session and return safely to the app that started authentication.
End Session
Principal ID
Specific session ID (optional)
Logout
Login again
Ready to end session
Production logout will clear tokens, revoke refresh sessions where needed, and return to the requesting app.