INVITATION ONLY
Your identity.
Verified in steps.
Your invitation fixes your existing Mirror identity and reconciled email. This page cannot select a role or enable a disabled identity.
No verified session.
01 / INVITATION
Request your mailbox token
Use the invitation provided by your operator. The message goes only to the already reconciled email, never an address entered here. Repeated requests do not replace the token. Open the message in this browser or paste its token in step 2.
02 / MAILBOX
Verify and create credentials
You need both tokens. Mailbox tokens expire after at most 10 minutes; invitations after 15 minutes. Expired or used tokens require a new operator invitation.
This creates credentials only. It does not grant application access or create a session.
03 / SIGN IN
Begin credential setup
04 / REGISTER
Register your required factor
Sign in with your password first. Ordinary access requires password plus TOTP, or a passkey with user verification. Privileged access requires a passkey; register it before requesting independent operator approval.
Registration never raises assurance. A registered passkey must complete a separate fresh authentication.
05 / AUTHENTICATE
Complete verification
For TOTP setup, confirm a code, sign out, then complete a fresh password login and a new TOTP code.
Privileged access: an independent operator must approve your enrollment. Then authenticate with your passkey again. An assertion before approval, email verification, and TOTP cannot replace this step. Privileged assertions expire after five minutes.
End this session
Global logout invalidates Identity sessions and advances the authorization epoch. Downstream event delivery remains a separate integration gate.