Sign-in: the coordinator and identity
Applies to: SimpleTwo 0.9.x, the directory role from 0.52 · Checked: 09.10.2026
With calendars, distribution groups and contacts merged into the directory role the platform
has two authenticators, and switches in the coordinator's console decide which one acts. This
page is the whole picture; the runbook for the switch itself is
Switching to sign-in through identity.
Two roles
coordinator | directory | |
|---|---|---|
| What it is | the control plane: the fleet, roles and permissions (RBAC), policy, product options, the console | the organisation's directory: accounts, groups and distribution groups, contacts and address books, calendars; SCIM, the LDAP source, the HRMS link |
| In the core | the authenticator: its own sign-in page and the broker to the organisation's identity provider (ADFS, Entra ID, Keycloak); it issues the sessions and tokens every service accepts | the directory: it holds the credentials for the coordinator — guests' passwords, app passwords for mail and CalDAV, the second factor — and verifies them on its request, as AD holds passwords while ADFS signs people in |
| With the ID product | keeps the fleet, roles and permissions; leaves the sign-in path once the platform token is switched | the provider: its own sign-in page with passwords, passkeys, push approval and e-mail codes; OpenID Connect and SAML for the company's applications; an LDAP server; the employee portal; the issuer of the platform's tokens |
The provider half of directory is turned on and off by the product option ID. While it
is off the role runs in directory mode: the provider's doors answer 409 provider_off, the
sign-in page offers the organisation's provider buttons alone, the LDAP server is not opened.
The role's names: its own, dir.<domain>, for everything the core has, and a second one,
id.<domain>, for sign-in when ID is on.
The switches
Every switch is in the coordinator's console, Settings. Each refuses to move forward while its conditions are unmet and says what stands in the way; switching back is always allowed.
| # | Where | Switch | Values | What it changes |
|---|---|---|---|---|
| 1 | Product options | ID | on · off | the directory role's mode: the provider, or the directory alone. It cannot go off while the platform token is identity |
| 2 | the "Sign-in" card (/admin/api/sign-in) | Who runs the sign-in | coordinator · identity | who draws the browser sign-in page: the coordinator's form and its SSO settings, or identity's page with passkeys, the second factor and its own brokering to the organisation's provider. The tokens come from the coordinator either way. Conditions: the directory public name answers, the coordinator's public URL is set; on the switch the coordinator registers the client platform on identity |
| 3 | the "Sign-in through identity" card | Platform token (platform_token) | hmac · identity | whose token every service accepts: the coordinator's (HMAC over the shared secret) or identity's (signed with its key, with a revocation feed). Conditions: identity's name announced, its issuing on (platform_issuer), keys pinned, the coordinator's public URL set, a break-glass account enrolled, the platform's bots holding identity credentials. Afterwards the console, the web client and the apps sign in through identity, and the coordinator mints no user token |
| 4 | the same card | Service token (service_token) | hmac · keys | what the services sign their calls to each other with: the shared secret or each host's own key |
| 5 | the same card | CalDAV and CardDAV (dav_auth) | calendar · identity | what a calendar or contacts program signs in with: the calendar's device passwords or identity's app passwords alone |
| 6 | the same card | Messaging directory (directory-source) | coordinator · identity | where chat takes people and groups from: the coordinator's directory events or the directory feed, which shows chat the provisioned people only |
Switches 2 and 3 are different things. The second changes only the page: who draws it. The third changes the issuer: after it a person has one session for every service, and sign-out, "that was not me", a password change and a block act everywhere at once. The third turns on only with ID on and runs the sign-in through identity itself, whatever the second says.
Coherent states
| State | ID | Who runs the sign-in | Platform token | What you get |
|---|---|---|---|---|
| The core | off | coordinator | hmac | sign-in through the organisation's provider on the coordinator's form; directory is the directory with the calendar; LDAP, passkeys and OIDC for applications are not offered |
| ID, identity's page | on | identity | hmac | people sign in on identity's page (passwords, passkeys, push), the company's applications through identity's OIDC and SAML; sessions are still the coordinator's, and one switch rolls back |
| The full switch | on | either | identity | identity is the issuer for every service; the console and the clients sign in through it; the coordinator keeps the fleet, roles and permissions. Runbook: Switching to sign-in through identity |
The other three switches (the service token, CalDAV and CardDAV, the messaging directory) do not depend on the first three and move as each service is ready.
Where to look next
- Products — what is in the core and what in ID
- Switching to sign-in through identity — the platform token runbook
- Sign-in through the organisation's provider, ADFS, SAML
- App passwords, Access to SimpleTwo