How sign-in works
Why Mojo Up AI Cloud issues its own tokens, how sessions and organisations fit together, and how accounts are kept from being taken over.
Mojo Up AI Cloud lets you sign in with an account you already have: Google, Microsoft, GitHub or Facebook, or a code sent to your email. Those providers only answer one question: who is this? Everything else, your account, your organisations, your roles and every token your browser, phone and workbenches use, belongs to Mojo Up AI Cloud and is kept in Australia.
That has three effects:
- One account, however you sign in. The console and the mobile app get the same kind of session from Mojo Up whichever provider you used.
- Your teams do not depend on one provider. You can add and remove sign-in methods without affecting your memberships.
- Single sign-on can be added without changing anything else. When it comes, it is one more way to prove who you are.
Signing in, step by step
- The console (or phone) creates a one-time secret and sends you to the provider, with a challenge derived from that secret (PKCE).
- You sign in at the provider. It sends you back to Mojo Up AI Cloud, which finds your account (or creates it, with your personal space) and returns you to the console with a one-time code that lasts 60 seconds.
- The console exchanges the code, together with its secret, for an access token and a refresh token. Nobody who intercepted the code alone could use it.
Mojo Up only ever returns you to addresses registered for the console and the phone app.
Sessions
- An access token lasts 15 minutes. The console renews it with the refresh token, which lasts 30 days.
- Every renewal replaces the refresh token. If an old refresh token is ever used again, which happens when one has been copied, Mojo Up ends the whole session.
- Sign out ends the session and every token issued in it.
- Signing in is rate-limited. Emailed codes are limited to five per address per hour, with five tries each.
Organisations
Your session is not tied to one organisation. Each request the console makes names the organisation it is for, and Mojo Up checks that you are a member, and what your role allows, every time. Switching organisation in the console changes which one it names.
Workbenches and nodes are different: each one is approved into exactly one organisation and holds a token for that organisation only. A workbench signed in to three organisations holds three tokens, one per space. Leaving a team, or being removed from it, ends the access of the workbenches you connected to it.
Linking accounts safely
A new sign-in method joins your existing account only when the provider has verified the email address it gives. Otherwise someone could create an account somewhere that does not check addresses, put your address on it, and reach your account. The rules for each provider are on Sign-in methods.
Invitations follow the same rule: accepting one needs a sign-in method whose verified address is the one the invitation was sent to.