[{"data":1,"prerenderedAt":291},["ShallowReactive",2],{"doc-features\u002Fpragma-auth":3,"content-query-OnPRPSsuxP":4},null,{"_path":5,"_dir":6,"_draft":7,"_partial":7,"_locale":8,"title":9,"description":10,"body":11,"_type":285,"_id":286,"_source":287,"_file":288,"_stem":289,"_extension":290},"\u002Fdocs\u002Ffeatures\u002Fpragma-auth","features",false,"","Pragma Sign In & Account","How Pragma users sign in, connect their CredVault account, and receive account-based access.",{"type":12,"children":13,"toc":278},"root",[14,22,28,35,40,65,70,90,95,128,134,139,168,174,179,184,202,208,213,256,262,267,272],{"type":15,"tag":16,"props":17,"children":19},"element","h1",{"id":18},"pragma-sign-in-account",[20],{"type":21,"value":9},"text",{"type":15,"tag":23,"props":24,"children":25},"p",{},[26],{"type":21,"value":27},"Pragma uses the CredVault account system. A user should not need a separate Pragma-only account. Their CredVault identity controls whether they can download, open, and use paid or free Pragma features.",{"type":15,"tag":29,"props":30,"children":32},"h2",{"id":31},"supported-sign-in-methods",[33],{"type":21,"value":34},"Supported Sign-In Methods",{"type":15,"tag":23,"props":36,"children":37},{},[38],{"type":21,"value":39},"Pragma can use the same account methods as the CredVault platform:",{"type":15,"tag":41,"props":42,"children":43},"ul",{},[44,50,55,60],{"type":15,"tag":45,"props":46,"children":47},"li",{},[48],{"type":21,"value":49},"Email and password.",{"type":15,"tag":45,"props":51,"children":52},{},[53],{"type":21,"value":54},"Google sign-in.",{"type":15,"tag":45,"props":56,"children":57},{},[58],{"type":21,"value":59},"GitHub sign-in.",{"type":15,"tag":45,"props":61,"children":62},{},[63],{"type":21,"value":64},"Account sessions created from the dashboard or billing flow.",{"type":15,"tag":23,"props":66,"children":67},{},[68],{"type":21,"value":69},"The frontend sign-in page is:",{"type":15,"tag":71,"props":72,"children":75},"pre",{"className":73,"code":74,"language":21,"meta":8,"style":8},"language-text shiki shiki-themes github-dark","\u002Fide-auth\n",[76],{"type":15,"tag":77,"props":78,"children":79},"code",{"__ignoreMap":8},[80],{"type":15,"tag":81,"props":82,"children":85},"span",{"class":83,"line":84},"line",1,[86],{"type":15,"tag":81,"props":87,"children":88},{},[89],{"type":21,"value":74},{"type":15,"tag":23,"props":91,"children":92},{},[93],{"type":21,"value":94},"The user-facing download and app pages connect to the same auth flow:",{"type":15,"tag":71,"props":96,"children":98},{"className":73,"code":97,"language":21,"meta":8,"style":8},"\u002Fpragma\n\u002Fdownload\n\u002Fpragma\u002Fworkspace\n",[99],{"type":15,"tag":77,"props":100,"children":101},{"__ignoreMap":8},[102,110,119],{"type":15,"tag":81,"props":103,"children":104},{"class":83,"line":84},[105],{"type":15,"tag":81,"props":106,"children":107},{},[108],{"type":21,"value":109},"\u002Fpragma\n",{"type":15,"tag":81,"props":111,"children":113},{"class":83,"line":112},2,[114],{"type":15,"tag":81,"props":115,"children":116},{},[117],{"type":21,"value":118},"\u002Fdownload\n",{"type":15,"tag":81,"props":120,"children":122},{"class":83,"line":121},3,[123],{"type":15,"tag":81,"props":124,"children":125},{},[126],{"type":21,"value":127},"\u002Fpragma\u002Fworkspace\n",{"type":15,"tag":29,"props":129,"children":131},{"id":130},"what-happens-during-sign-in",[132],{"type":21,"value":133},"What Happens During Sign In",{"type":15,"tag":23,"props":135,"children":136},{},[137],{"type":21,"value":138},"When a user signs in:",{"type":15,"tag":140,"props":141,"children":142},"ol",{},[143,148,153,158,163],{"type":15,"tag":45,"props":144,"children":145},{},[146],{"type":21,"value":147},"CredVault verifies the user.",{"type":15,"tag":45,"props":149,"children":150},{},[151],{"type":21,"value":152},"The backend creates or confirms the user's session.",{"type":15,"tag":45,"props":154,"children":155},{},[156],{"type":21,"value":157},"The user's plan and access are checked.",{"type":15,"tag":45,"props":159,"children":160},{},[161],{"type":21,"value":162},"Pragma receives a valid app session.",{"type":15,"tag":45,"props":164,"children":165},{},[166],{"type":21,"value":167},"The desktop app can load the user's settings, plan, Drive access, and backend-connected features.",{"type":15,"tag":29,"props":169,"children":171},{"id":170},"paid-and-free-access",[172],{"type":21,"value":173},"Paid And Free Access",{"type":15,"tag":23,"props":175,"children":176},{},[177],{"type":21,"value":178},"Free users should be able to install and open Pragma with the limits assigned to the free plan. Paid users should be routed through billing when they choose a paid plan.",{"type":15,"tag":23,"props":180,"children":181},{},[182],{"type":21,"value":183},"The important behavior is:",{"type":15,"tag":41,"props":185,"children":186},{},[187,192,197],{"type":15,"tag":45,"props":188,"children":189},{},[190],{"type":21,"value":191},"Free plan: let the user continue after sign-in.",{"type":15,"tag":45,"props":193,"children":194},{},[195],{"type":21,"value":196},"Paid plan: route the user to payment first, then return them to download or app access.",{"type":15,"tag":45,"props":198,"children":199},{},[200],{"type":21,"value":201},"Enterprise plan: require organization or seat provisioning.",{"type":15,"tag":29,"props":203,"children":205},{"id":204},"account-data-users-should-see",[206],{"type":21,"value":207},"Account Data Users Should See",{"type":15,"tag":23,"props":209,"children":210},{},[211],{"type":21,"value":212},"Inside the app and dashboard, a user should be able to see:",{"type":15,"tag":41,"props":214,"children":215},{},[216,221,226,231,236,241,246,251],{"type":15,"tag":45,"props":217,"children":218},{},[219],{"type":21,"value":220},"Name.",{"type":15,"tag":45,"props":222,"children":223},{},[224],{"type":21,"value":225},"Email.",{"type":15,"tag":45,"props":227,"children":228},{},[229],{"type":21,"value":230},"Role or plan.",{"type":15,"tag":45,"props":232,"children":233},{},[234],{"type":21,"value":235},"Account ID.",{"type":15,"tag":45,"props":237,"children":238},{},[239],{"type":21,"value":240},"Current operating system.",{"type":15,"tag":45,"props":242,"children":243},{},[244],{"type":21,"value":245},"Days active or clocked in.",{"type":15,"tag":45,"props":247,"children":248},{},[249],{"type":21,"value":250},"Pragma access state.",{"type":15,"tag":45,"props":252,"children":253},{},[254],{"type":21,"value":255},"Settings and personalization options.",{"type":15,"tag":29,"props":257,"children":259},{"id":258},"security-notes",[260],{"type":21,"value":261},"Security Notes",{"type":15,"tag":23,"props":263,"children":264},{},[265],{"type":21,"value":266},"Pragma should never expose raw passwords, payment secrets, OAuth secrets, or backend service tokens in the app. The desktop app should only receive the user session and the minimum tokens needed for app features.",{"type":15,"tag":23,"props":268,"children":269},{},[270],{"type":21,"value":271},"Users should be able to sign out from the desktop app and invalidate the local session.",{"type":15,"tag":273,"props":274,"children":275},"style",{},[276],{"type":21,"value":277},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}",{"title":8,"searchDepth":112,"depth":112,"links":279},[280,281,282,283,284],{"id":31,"depth":112,"text":34},{"id":130,"depth":112,"text":133},{"id":170,"depth":112,"text":173},{"id":204,"depth":112,"text":207},{"id":258,"depth":112,"text":261},"markdown","content:docs:features:pragma-auth.md","content","docs\u002Ffeatures\u002Fpragma-auth.md","docs\u002Ffeatures\u002Fpragma-auth","md",1786114913321]