Skip to main content

Sign-in: the coordinator and identity

Applies to: SimpleTwo 0.9.x, the directory role from 0.52 · Checked: 09.10.2026

With calendars, distribution groups and contacts merged into the directory role the platform has two authenticators, and switches in the coordinator's console decide which one acts. This page is the whole picture; the runbook for the switch itself is Switching to sign-in through identity.

Two roles​

coordinatordirectory
What it isthe control plane: the fleet, roles and permissions (RBAC), policy, product options, the consolethe organisation's directory: accounts, groups and distribution groups, contacts and address books, calendars; SCIM, the LDAP source, the HRMS link
In the corethe authenticator: its own sign-in page and the broker to the organisation's identity provider (ADFS, Entra ID, Keycloak); it issues the sessions and tokens every service acceptsthe directory: it holds the credentials for the coordinator — guests' passwords, app passwords for mail and CalDAV, the second factor — and verifies them on its request, as AD holds passwords while ADFS signs people in
With the ID productkeeps the fleet, roles and permissions; leaves the sign-in path once the platform token is switchedthe provider: its own sign-in page with passwords, passkeys, push approval and e-mail codes; OpenID Connect and SAML for the company's applications; an LDAP server; the employee portal; the issuer of the platform's tokens

The provider half of directory is turned on and off by the product option ID. While it is off the role runs in directory mode: the provider's doors answer 409 provider_off, the sign-in page offers the organisation's provider buttons alone, the LDAP server is not opened. The role's names: its own, dir.<domain>, for everything the core has, and a second one, id.<domain>, for sign-in when ID is on.

The switches​

Every switch is in the coordinator's console, Settings. Each refuses to move forward while its conditions are unmet and says what stands in the way; switching back is always allowed.

#WhereSwitchValuesWhat it changes
1Product optionsIDon · offthe directory role's mode: the provider, or the directory alone. It cannot go off while the platform token is identity
2the "Sign-in" card (/admin/api/sign-in)Who runs the sign-incoordinator · identitywho draws the browser sign-in page: the coordinator's form and its SSO settings, or identity's page with passkeys, the second factor and its own brokering to the organisation's provider. The tokens come from the coordinator either way. Conditions: the directory public name answers, the coordinator's public URL is set; on the switch the coordinator registers the client platform on identity
3the "Sign-in through identity" cardPlatform token (platform_token)hmac · identitywhose token every service accepts: the coordinator's (HMAC over the shared secret) or identity's (signed with its key, with a revocation feed). Conditions: identity's name announced, its issuing on (platform_issuer), keys pinned, the coordinator's public URL set, a break-glass account enrolled, the platform's bots holding identity credentials. Afterwards the console, the web client and the apps sign in through identity, and the coordinator mints no user token
4the same cardService token (service_token)hmac · keyswhat the services sign their calls to each other with: the shared secret or each host's own key
5the same cardCalDAV and CardDAV (dav_auth)calendar · identitywhat a calendar or contacts program signs in with: the calendar's device passwords or identity's app passwords alone
6the same cardMessaging directory (directory-source)coordinator · identitywhere chat takes people and groups from: the coordinator's directory events or the directory feed, which shows chat the provisioned people only

Switches 2 and 3 are different things. The second changes only the page: who draws it. The third changes the issuer: after it a person has one session for every service, and sign-out, "that was not me", a password change and a block act everywhere at once. The third turns on only with ID on and runs the sign-in through identity itself, whatever the second says.

Coherent states​

StateIDWho runs the sign-inPlatform tokenWhat you get
The coreoffcoordinatorhmacsign-in through the organisation's provider on the coordinator's form; directory is the directory with the calendar; LDAP, passkeys and OIDC for applications are not offered
ID, identity's pageonidentityhmacpeople sign in on identity's page (passwords, passkeys, push), the company's applications through identity's OIDC and SAML; sessions are still the coordinator's, and one switch rolls back
The full switchoneitheridentityidentity is the issuer for every service; the console and the clients sign in through it; the coordinator keeps the fleet, roles and permissions. Runbook: Switching to sign-in through identity

The other three switches (the service token, CalDAV and CardDAV, the messaging directory) do not depend on the first three and move as each service is ready.

Where to look next​