Principals
| Name | Type | Disabled | MFA | Groups | Roles | Direct Permissions | Actions |
|---|
Create Principal
Groups
| Name | Description | Roles | Actions |
|---|
Create Group
Roles
| Name | Permissions | Actions |
|---|
Create Role
Clients
| Client ID | Display Name | Public | Redirect URIs | Scopes | Consent | Logout | Actions |
|---|
Create Client
External Auth Providers
| Name | Source | Client | Enabled | Auto-Provision | Actions |
|---|
Create Provider
External providers let accounts sign in via OAuth2/OIDC. The account is keyed by email: any provider reporting the same email signs into the same local account, and a first-time email auto-provisions a principal.
Realms
A realm is a Kubernetes namespace scoping this console's data (principals, groups, roles, clients, and its OIDC signing key). Creating one labels a new namespace and tolerates an existing one (any workloads already present are kept). Deleting a realm "releases" it by default — it removes every Ipseity-managed object and the realm label, keeping the namespace and any non-Ipseity workloads. Use the purge action to delete the namespace and everything in it.
| Realm | Ipseity | Bootstrap | Counts | Active Key | Actions |
|---|
My Account
Profile
Loading...
Change Password
MFA (Authenticator App)
Loading...
Scan this URI with an authenticator app, then confirm with the generated 6-digit code.
Linked External auth providers
Loading...
Active Sessions
| Client | Scope | Issued | Expires | Actions |
|---|
OAuth2/OIDC
Core protocol endpoints:
GET /oauth/authorize POST /oauth/authorize POST /oauth/authorize/consent POST /oauth/token POST /oauth/introspect POST /oauth/revoke GET /oidc/.well-known/openid-configuration GET /oidc/jwks GET /oidc/userinfo GET /oidc/logout