MIRROR IDENTITYSTAGING · REVIEW REQUIRED

INVITATION ONLY

Your identity.
Verified in steps.

Your invitation fixes your existing Mirror identity and reconciled email. This page cannot select a role or enable a disabled identity.

APPLICATION ACCESS

No verified session.

01 / INVITATION

Request your mailbox token

Use the invitation provided by your operator. The message goes only to the already reconciled email, never an address entered here. Repeated requests do not replace the token. Open the message in this browser or paste its token in step 2.

02 / MAILBOX

Verify and create credentials

You need both tokens. Mailbox tokens expire after at most 10 minutes; invitations after 15 minutes. Expired or used tokens require a new operator invitation.

This creates credentials only. It does not grant application access or create a session.

03 / SIGN IN

Begin credential setup

04 / REGISTER

Register your required factor

Sign in with your password first. Ordinary access requires password plus TOTP, or a passkey with user verification. Privileged access requires a passkey; register it before requesting independent operator approval.

Registration never raises assurance. A registered passkey must complete a separate fresh authentication.

05 / AUTHENTICATE

Complete verification

For TOTP setup, confirm a code, sign out, then complete a fresh password login and a new TOTP code.

Privileged access: an independent operator must approve your enrollment. Then authenticate with your passkey again. An assertion before approval, email verification, and TOTP cannot replace this step. Privileged assertions expire after five minutes.

End this session

Global logout invalidates Identity sessions and advances the authorization epoch. Downstream event delivery remains a separate integration gate.