Sign-in
GitHub OAuth
Required scopes: repo (full read/write to private repos). After OAuth, the provider credential remains server-side in the session/project record and is never placed in the browser URL. Project admins can configure or replace a project credential from Project management.
Project membership determines access. Administrators can invite users, manage project credentials and edit schema; content editors are restricted to permitted content paths.
Google OAuth (invite-only)
Google users appear only after an administrator invites them by email. The short-lived invite is bound to the invited address. After Google verifies the account email, the user is added to project_users as an editor. Editors cannot edit schema, set project credentials or invite others.
Local folder in the web editor
For local work, the web editor uses the browser File System Access API. The user explicitly chooses a folder and the browser mediates subsequent reads and writes. This is a web workflow; the parked desktop application is not required.