Authentication

Choose the credential that matches the caller and trust boundary.

Linea uses distinct credentials because an Operator backend, an Operator application, and an End User do not have interchangeable authority.

Credential selection

CallerCredentialScope
Operator control planeAuthenticated member sessionWorkspace role and membership
Operator server integrationWorkspace keyExplicit workspace operations
Application backendApplication keyOne deployed Application and runtime resources
End-user browser or mobile appEnd-User SessionOne subject, Application, audience, and short lifetime

Application keys cannot change identity trust configuration or cross into another Application. Workspace keys cannot impersonate End Users. An End-User Session is a short-lived capability, not a Linea account session.

End-user authorization

Begin authorization

The Application starts an authorization request for an external subject using its server-side Application Key.

Verify identity

Linea validates the configured issuer and binds the external identity to the canonical subject within the workspace.

Exchange the authorization result

The client exchanges the short-lived result for an opaque End-User Session.

Prove possession on each request

DPoP binds requests to the client key, method, and target URL so copying the session value alone is insufficient.

See trust boundaries for the full identity and credential map.

On this page