Auth control plane
DiyaOS
Passwordless identity
Bootstrap
Create the first OS admin.
Login
Passkey, FIDO key, or OTP fallback.
Verify
OTP step-up and periodic checks.
Recover
No-password recovery entry point.
Profile
Security profile and access posture.
Posture
Recovery readiness and backup path.
Replace
Lost-device credential replacement.
Notify
Security event preferences.
Invite
Accept tenant or admin invitations.
Request
Ask for platform or tenant access.
Authorize
Approve app access and redirect.
Device
Register passkeys and security keys.
Scope
Choose OS, platform, tenant, or app context.
Session
Review current session and trusted device state.
Logout
End this browser session.
DiyaOS Auth
Security Notifications
Choose which authentication, recovery, session, and access events should reach a user when the notification service is wired.
Notification Profile
Principal
Security Events
New sign-in
Alert when a passkey or FIDO login creates a new session.
OTP issued
Alert when a verification, step-up, or recovery code is created.
Credential added
Alert when a passkey or security key is registered.
Recovery started
Alert when lost-device or account-recovery flow begins.
Access changed
Alert when role, scope, tenant, or app access changes.
Session revoked
Alert when logout or admin revocation ends a session.
Channels
Email
Use the principal email until the communications service owns verified delivery preferences.
In-app
Show security events inside the OS profile and future global notification center.
Save preferences
Security profile
Sessions
Preferences ready
Security preferences are stored locally until the shared notification preference API is available.