Isolated operator plane

Administration requires more than a signed-in identity.

The Shared Auth operator surface is separate from customer authentication. It must require an allow-listed administrator, the correct realm and organization, fresh assurance, CSRF protection, and authoritative server-side authorization.

Restricted administration surfaceadmin.ores-shared-auth.com
PUBLIC HOSTexact match
EDGECloudflare Workerhost → service
AUTHORITYShared Authidentity ≠ authorization

Fail closed until the admin realm is ready.

This static handoff does not render users, sessions, roles, secrets, or audit records. The deployed administration service replaces it only after realm-isolation, origin, certificate, and revocation gates pass.

Admin API boundary

The canonical machine-facing hostname isapi-admin.ores-shared-auth.com. The compatibility hostnameadmin-api.ores-shared-auth.com reaches the same service directly so mutating requests are not redirected and replayed.