Sign in and choose an instance
The cockpit opens on the sign-in page. Any page you open while signed out also brings you here, and so does a session that ends or that the server rejects.
Sign-in methods
When the page loads, the cockpit asks the backend which sign-in methods it offers.
The backend answers on its /auth/config endpoint.
| Method | When it appears |
|---|---|
| Email and Password | Always. |
| Google single sign-on | Only when the backend reports Google sign-in as configured. An or divider separates it from the password form. |
If the cockpit cannot reach the sign-in service, the Google button is replaced by Single sign-on is unavailable — the sign-in service could not be reached. You can still sign in with your email and password. If the backend reports that it has no single sign-on, the page shows no Google button and no message.
With Google, select the Google button and complete Google’s own dialog. A browser that is already signed in to Google may complete the sign-in without asking.
Two-factor verification
The MFA Verification page asks you to Enter the 6-digit code from your authenticator. Type the code into the six boxes. The code is submitted as soon as the last digit is in. Screen readers announce Verifying code while it is checked.
Cancel / Return to Login abandons the attempt. You can only reach this page while a second-factor challenge is waiting. Otherwise the cockpit sends you back to sign-in.
Choose an instance
An instance is the FACE deployment you are working in. The SELECT INSTANCE page (Choose an active instance to continue.) lists every instance your account has a grant on, under Choose an instance. The refresh button (Refresh instances) reads the list again.
Each card shows:
- the product and the instance name;
- the tenant;
- your role: Admin, Editor, Viewer or Service account;
- the status;
- how long your access lasts, for example Access does not expire.
A card marked Current is the instance you are already using. Anything the server did not report is shown as not stated, for example Role not stated.
Select a card to open it, even when it is the only one. The cockpit then starts a session fetch and a posture assessment for that instance and opens Fetch. Your role on the instance decides whether you see the Admin entry in the navigation.
When the list is empty or fails
| You see | Meaning | What to do |
|---|---|---|
| No instance grants you access — Ask an admin of the instance you need to invite you. | The server answered and you hold no grant on any instance. | Ask an admin of that instance to invite you. |
| This deployment has no instances to choose from. | The deployment itself offers no instances. | Ask your platform operator. |
| Could not be read, followed by a reason and Retry | The list could not be read. This does not mean you have no instances. | Read the reason, then select Retry. |
Signing out
Sign out from your profile. Signing out closes any dialogs that were open and returns you to this page.
RPCs behind these pages
IdentityService.Login: password, Google and the second-factor step.IdentityService.Logout.runink.ui.profile.v1.ProfileService.ListInstances: the instance list.
See the API reference.