Skip to content

Sign in and choose an instance

The cockpit opens on the sign-in page. Any page you open while signed out also brings you here, and so does a session that ends or that the server rejects.

Sign-in methods

When the page loads, the cockpit asks the backend which sign-in methods it offers. The backend answers on its /auth/config endpoint.

MethodWhen it appears
Email and PasswordAlways.
Google single sign-onOnly when the backend reports Google sign-in as configured. An or divider separates it from the password form.

If the cockpit cannot reach the sign-in service, the Google button is replaced by Single sign-on is unavailable — the sign-in service could not be reached. You can still sign in with your email and password. If the backend reports that it has no single sign-on, the page shows no Google button and no message.

### Enter your email and password Type your address in **Email** and your password in **Password**. The eye button (**Show password** / **Hide password**) reveals what you typed. Press Enter in the email field to move to the password field. ### Select Sign In Or press Enter in the password field. While the server checks your credentials, the button shows a spinner. Screen readers announce it as **Signing in**. ### Complete the second factor, if asked If your account has an authenticator enrolled, the cockpit opens the MFA page (see below). ### Choose an instance After a successful sign-in you land on **SELECT INSTANCE**.

With Google, select the Google button and complete Google’s own dialog. A browser that is already signed in to Google may complete the sign-in without asking.

Two-factor verification

The MFA Verification page asks you to Enter the 6-digit code from your authenticator. Type the code into the six boxes. The code is submitted as soon as the last digit is in. Screen readers announce Verifying code while it is checked.

Cancel / Return to Login abandons the attempt. You can only reach this page while a second-factor challenge is waiting. Otherwise the cockpit sends you back to sign-in.

Choose an instance

An instance is the FACE deployment you are working in. The SELECT INSTANCE page (Choose an active instance to continue.) lists every instance your account has a grant on, under Choose an instance. The refresh button (Refresh instances) reads the list again.

Each card shows:

  • the product and the instance name;
  • the tenant;
  • your role: Admin, Editor, Viewer or Service account;
  • the status;
  • how long your access lasts, for example Access does not expire.

A card marked Current is the instance you are already using. Anything the server did not report is shown as not stated, for example Role not stated.

Select a card to open it, even when it is the only one. The cockpit then starts a session fetch and a posture assessment for that instance and opens Fetch. Your role on the instance decides whether you see the Admin entry in the navigation.

When the list is empty or fails

You seeMeaningWhat to do
No instance grants you access — Ask an admin of the instance you need to invite you.The server answered and you hold no grant on any instance.Ask an admin of that instance to invite you.
This deployment has no instances to choose from.The deployment itself offers no instances.Ask your platform operator.
Could not be read, followed by a reason and RetryThe list could not be read. This does not mean you have no instances.Read the reason, then select Retry.

Signing out

Sign out from your profile. Signing out closes any dialogs that were open and returns you to this page.

RPCs behind these pages

  • IdentityService.Login: password, Google and the second-factor step.
  • IdentityService.Logout.
  • runink.ui.profile.v1.ProfileService.ListInstances: the instance list.

See the API reference.