> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# People and sign-in

> Sessions, email codes, shared organization access, and API tokens.

Sign-in is an email and a password for a person in one organization. People you add share that organization's projects, AWS connection, and GitHub connection.

## The session

A browser session uses a cookie that is `HttpOnly` and `SameSite=Lax`. In production the cookie is also `Secure`, so the browser sends it only over HTTPS. JavaScript on the page cannot read the cookie.

A request that changes data from the browser also has to present a CSRF token from `GET /api/csrf`. A request that authenticates with `Authorization: Bearer` is not a cookie session, so it is not checked with that CSRF token. The token itself is the credential. GitHub webhooks are checked with the signature described on [GitHub](/security/github), not with a session.

Signing out ends that session. A person or an organization that has been removed can no longer sign in. A removed email cannot be registered again.

## Confirming the email

Sign-up sends a 6-digit code. The code expires in 10 minutes, and five wrong attempts invalidate it. Springwinter stores an HMAC of the code, not the code. Password reset uses the same shape. See [Credentials](/security/credentials).

Google and Microsoft sign-in are not enabled.

## People in the organization

Any person in the organization can add another person by email, or remove someone else. You cannot remove yourself. There are no roles and no per-project permission levels. Someone you add can open the same projects, assume the same AWS role through Springwinter, and deploy from the same GitHub installation.

The team page shows the names and email addresses of the other people.

An added person receives a generated password by email. They can change it after signing in. Changing a password asks for the new password twice. It does not ask for the current password.

## API tokens

A person can create an API token for the organization. The secret is shown once. Scripts send it as a bearer token. It can do what a person in the organization can do. Revoke it from **Settings → API Tokens** when it is no longer used, or if it has been exposed. See [Credentials](/security/credentials).

## What is not a control

An identifier in a URL is not a permission. Every read and every change is checked against the signed-in person and their organization. A resource id from another organization does not open that resource.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.