Admin API boundary
The canonical machine-facing hostname isapi-admin.ores-shared-auth.com. The compatibility hostnameadmin-api.ores-shared-auth.com reaches the same service directly so mutating requests are not redirected and replayed.
Isolated operator plane
The Shared Auth operator surface is separate from customer authentication. It must require an allow-listed administrator, the correct realm and organization, fresh assurance, CSRF protection, and authoritative server-side authorization.
This static handoff does not render users, sessions, roles, secrets, or audit records. The deployed administration service replaces it only after realm-isolation, origin, certificate, and revocation gates pass.
The canonical machine-facing hostname isapi-admin.ores-shared-auth.com. The compatibility hostnameadmin-api.ores-shared-auth.com reaches the same service directly so mutating requests are not redirected and replayed.