Authentication
Authentication (RPL)
Section titled “Authentication (RPL)”Audience: domain, product
Status: specced
Owns: product + backend
Depends on: Orchestrator, Domain — User
Product intent
Section titled “Product intent”- Create account, verify account, forgot password, reset password.
- Verification uses OTP (not email magic links).
- Sign-in: password and Google (Gmail).
- Shared auth/JWT issuance is intended to live in the Orchestrator; CAP consumes the same JWT.
See also
Section titled “See also”- Screens / flows → Experience flows — account & identity
- Client contract → API overview — Auth
- Audience copy → Narrative — Account and sign-in