DevOps

Phase 2A

Owner setup and mandatory authenticator enrollment

The first DevOps platform owner is activated only after password creation, authenticator verification, and recovery-code acknowledgment. Public registration remains disabled.

This route accepts a one-time bootstrap token, converts it into a short-lived HttpOnly setup session, and removes the raw bootstrap token from the browser URL before enrollment continues.

Production owner onboarding remains guarded. Login-time MFA challenges are still deferred to Phase 2B.

Owner setup

This secure owner-setup link is invalid, expired, or has already been used.