Identity and access

Sign-in and sessions

Passkeys first, passwords and two-step sign-in, several accounts in one browser, and how the apps share an account session.

Passkeys

A passkey signs you in with your device (Touch ID, Face ID, Windows Hello, a phone or a security key) instead of a password. It can't be phished or reused on another site, and there's nothing to type.

The sign-in page at id.cactive.com.au leads with passkeys:

  • Choose Sign In with a Passkey. You don't need to type your email.
  • Or select the email field: browsers that support it list your passkeys there (passkey autofill).

New accounts start with a passkey too: accepting an invite offers Create a Passkey and Join, and the account is created with that passkey and no password. Use a Password Instead creates it with a password. Either way you give your date of birth, which stays private to your account (Accounts).

Add more passkeys (one per device, or a security key) on your account page under Passkeys, and remove them from the same list. Passkeys work alongside a password. A passkey that was removed from your account is reported to the browser, which stops offering it.

Passwords

Passwords are at least 12 characters (up to 256). Change yours on your account page at https://id.cactive.com.au under Password. Passwords are stored as salted scrypt hashes.

After 10 wrong passwords for an address within 15 minutes, password sign-in for that address pauses until the 15 minutes are over, even with the right password. Passkeys keep working.

Securing your account

When you sign in with a password and your account has neither a passkey nor two-step sign-in, Let's Secure Your Account comes up before you continue:

  • Set Up a Passkey (recommended): one prompt from your device, and you can sign in with it from then on.
  • Use an Authenticator App: scan the QR code with Cactive Authenticator (recommended) or any authenticator app, enter its code and save your backup codes. Signing in with your password then also asks for a code.
  • Skip for 7 days: you're asked again at a sign-in after that.

It isn't shown when you sign in to a phone app or add your mailbox to an Apple device: those go straight back.

Two-step sign-in

With two-step sign-in, signing in with your password also asks for a 6-digit code. A passkey doesn't: it's already two factors. The command line, phone apps and connected apps sign in through id.cactive.com.au in a browser, so they ask for it too.

If your account has a passkey, the step after your password also offers Sign In with a Passkey Instead, for when you can't read the code (for example when your authenticator is the phone app you're signing in from). It asks for one of your account's passkeys and signs you in with it in place of the code; a request sent to your phone is withdrawn.

Authenticator app

The Authenticator app page links to the Cactive Authenticator phone app, with a QR code to open the link on your phone.

  1. On your account page, under Authenticator app, choose Set up.
  2. Scan the QR code with an authenticator app (any app with time-based codes), or type in the key shown under it.
  3. Enter the code the app shows, then save your backup codes.

Codes change every 30 seconds. The code before and after the current one are accepted too, in case your phone's clock is a little off, and each code works once. After 5 wrong codes in 15 minutes, codes are refused for the rest of that time; passkeys keep working.

To remove the app, choose Remove and enter a code from it or a backup code (not needed within 5 minutes of signing in). Your backup codes stop working with it.

Backup codes

Setting up the app gives you 10 backup codes, shown once: copy or download them. If you don't have your phone, choose Use a Backup Code when asked for a code. Each one works once, and you're told when 3 or fewer are left. Make new codes replaces them all.

Text codes

Two-step sign-in by text sends the code to your primary phone number (Notifications). With an authenticator app too, the app is asked for first; choose Text Me a Code Instead to get a text.

Sign-in approvals

With Cactive Authenticator set up to approve sign-ins, the step after your password is Check Your Phone: the page shows a two-digit number and your phone gets a request. Tap the same number there (among three), confirm with Face ID or the passcode, and the page continues by itself, with no code to type. Send Another Request sends a new one, and the codes are still offered: Enter a Code from the App Instead, Use a Backup Code, Text Me a Code Instead. From the code page, Get a Request on Your Phone Instead goes back to a request.

  • Approvals need two-step sign-in on (an authenticator app or texts), so a code is always there to fall back to.
  • A request lasts 2 minutes and works once, for the browser that asked. Declining it, or tapping another number, blocks the sign-in.
  • Up to 5 requests in 15 minutes. After 3 are declined in 15 minutes, requests pause for an hour and signing in asks for a code.
  • On your account page under Authenticator app, Sign-In Approvals turns them on or off, resumes a pause, and lists the phones that approve (name, when added and last used, where the key is kept), each with Remove. Phones are added in the app.

A sign-in approved on a phone counts as two-step for organization sign-in policies (password+approval).

Authenticator secrets are encrypted (AES-256-GCM) and backup codes are stored as keyed hashes.

Sessions

Signing in at id.cactive.com.au starts your account session in that browser, which lasts 7 days.

Cloud, Git, Caity, Notes, Mail, Tasks, Maps and Admin each sign in through it: the first time you open one, it sends you to id.cactive.com.au (where you choose the account) and back, then keeps its own tokens:

TokenLifetime
Access token15 minutesSent with every request the app makes for you.
Refresh token30 daysRenews the access token. Each use replaces it with a new one.

Each app stores its tokens in cookies on its own hostname only (HttpOnly, Secure, SameSite=Lax, named with the __Host- prefix), so no other app, and none of your deployments, can read or replace them.

Your organizations and roles travel in the access token, so a change to them reaches an app within 15 minutes.

Phone and tablet apps

The iOS and Android apps sign in through id.cactive.com.au in the system browser, then each app keeps its own sign-in on the phone: a 30-day refresh token that renews with use, independent of the browser's session. With each sign-in and renewal the app sends the phone's install id (the same for every app on the phone), its model and system version, and the app's version.

Each app registers itself for push notifications when you sign in, asking for permission the first time. The registration belongs to that app's sign-in: when the app is signed out, it stops receiving notifications.

Devices and sessions

Your account page lists where you're signed in, under Devices in its sidebar:

  • Devices: each phone and tablet (model, system, last active and approximate place) with the apps signed in on it, their versions, when they signed in, and whether notifications are on. Sign Out next to an app signs that app out; Sign Out of All Apps signs out every app on the phone. Machines signed in with the command line and Apple devices are listed there too.
  • Browser Sessions: each browser's browser and system, approximate place from its network address, the address, when it signed in and was last seen.
  • Sign-In History: every sign-in and every failed attempt on your account in the last 90 days, with the device, address, approximate place and how you signed in (password, passkey, the second step). A sign-in whose browser is still signed in can be signed out there.

Places come from the network address and are approximate; where none can be told, the address is shown alone. IP location data: DB-IP (CC BY 4.0), where the edge gives none.

Browsers, phone apps and command-line machines are signed out separately. A signed-out phone app or machine stops at once: its tokens stop working and it gets no more notifications.

Sign out

  • Sign out in an app removes that app's tokens (a phone app also ends its sign-in and its notifications). Your account session continues, so other apps keep working and the next sign-in doesn't ask for your password.
  • Sign out on your account page ends that account's session in this browser, and the web apps signed in with it from this browser sign out within 15 minutes. Other accounts signed in on the browser stay signed in. Phone apps stay signed in; sign them out under Phones and tablets.

Several accounts

One browser can stay signed in to several accounts (up to 10), each with its own session: each one shows under Browser Sessions of its account, and signing one out leaves the others.

When a web app sends you to id.cactive.com.au to sign in and the browser has a signed-in account, Choose an Account asks which one to use for that app:

  • Select an account to continue with it. It becomes the browser's current account: the one your account page shows, and the one apps continue with if you turn the chooser off.
  • Use Another Account signs in with a different account (passkey or password), keeping the others signed in.
  • The ⋮ menu next to an account signs that account out of the browser; Sign out of all accounts signs every one out.

Switching apps with the app switcher (the grid in the header) doesn't ask either: the app you open continues with the account you were using in the app you came from, as long as that account is still signed in on the browser. Phone apps never ask: they continue with the account that's signed in, or show the sign-in page. Your own apps (Sign in with) and MCP clients ask too, before their consent page.

To stop being asked, turn off Ask which account to use under Browser Sessions → Account Chooser: apps then continue with the account you're using. Apps can still ask for the chooser with prompt=select_account, prompt=none never shows it, and prompt=login asks for your password or passkey again even when you're signed in.

Using another account

Use Another Account on an approval or consent page (an agent, the command line, an Apple device, a connected app) opens Choose an Account and brings you back to the same page with the account you pick or sign in with. Nothing is signed out on the way. To switch the account your account page shows, use Switch account under Browser Sessions → Account Chooser.

Standards

id.cactive.com.au is an OAuth 2.1 issuer: authorization code flow with PKCE (S256) only, ES256-signed JWT access tokens, single-use authorization codes and rotating refresh tokens. The platform's own apps use /authorize and /token; your apps (Sign in with) and MCP clients (MCP server) use /oauth/*, described by https://id.cactive.com.au/.well-known/openid-configuration (also at /.well-known/oauth-authorization-server). Keys are at https://id.cactive.com.au/.well-known/jwks.json. Agents log in with the device authorization grant (Login and approval).

Connected apps

Your account page lists the apps and MCP clients you signed in to under Connected apps. Remove ends that app's access: its refresh tokens stop working at once, and its current access token within the hour.

Sign-ins in the audit log

Sign-ins and failed sign-ins (password, passkey, a wrong two-step code or a request declined on a phone) are recorded in the audit log of every organization you belong to, as account.sign_in and account.sign_in_failed. Turning an authenticator app on or off, making new backup codes and signing in with a backup code are recorded as account.mfa_totp_enabled, account.mfa_totp_disabled, account.backup_codes_regenerated and account.backup_code_used. Sign-in approvals record account.sign_in_approval_approve and account.sign_in_approval_deny (with what was signing in), account.approval_device_add and account.approval_device_remove, account.sign_in_approvals_on, account.sign_in_approvals_off and account.sign_in_approvals_resume, and account.sign_out_everywhere. Phone apps signing in and out are recorded as account.mobile_sign_in and account.mobile_sign_out.

Rate limits

Sign-in pages and token endpoints are rate limited per IP address: past the limit, requests get 429 with Retry-After for a few minutes (Limits).