GPlatform SSO terms
What your GPlatform SSO account is, how organisations, teams and access grants work, the ways in and the one control that ends every session, what the applications that sign you in through it may learn, and how the clauses of the general terms apply here.
This applies alongside the general terms of service and privacy policy. Where they differ on a point about GPlatform SSO specifically, this page wins.
What this covers
GPlatform SSO is the identity layer we run for our products. It holds the person, the organisations and teams they belong to, the sessions they have open in every product at once, and which products each of them may reach, in which role. Applications sign people in through it: our own products, such as the GPlatform products and the G Open registries, software we run, and the applications of other organisations through OpenID Connect.
These terms cover your account and what you do in GPlatform SSO itself. What you do inside a product you reach through it is governed by that product's own terms. Both sit under the general terms of service, which carry everything that is not particular to GPlatform SSO: the licence to your content, moving accounts, changes to the terms, restrictions and ending, warranty, liability and governing law. They are not restated here.
How we process your personal data is in the privacy notice. Where an organisation uses GPlatform SSO for its own people, the processing annex applies between us and that organisation.
A service, not software to run
GPlatform SSO is licensed under the Elastic License 2.0 and is not offered for you to run yourself. For as long as your contract runs, you may use the hosted service as these terms describe, as the general terms set out.
The client library applications use to speak to it, @ghub/gpsso-sdk, is published under the Elastic License 2.0 as well. Its own licence governs it, and nothing here restricts that licence.
Your account
One account above every product. Registering on the GPlatform SSO console at sso.gplatform.org makes a full account: your name if you give one, your email address and a password of at least 12 characters. Nothing works until you confirm the address with the link we send you, which is valid for one hour. An address can be claimed by one full account only.
Age. You must be at least 16 to hold an account. If you are under 18, you confirm at sign-up that a parent or guardian agrees; without that agreement the contract is not valid (Sections 107 and 108 BGB).
An account made inside a product stays in that product. Some of our products let you sign up on their own pages. That makes a real account in GPlatform SSO, with its own password and sessions, but it signs in to that one product and nowhere else and cannot open the console. It becomes a full account only if you accept an offer to join it to another account (see "Joining two accounts" below).
Addresses. You may add several addresses and choose which confirmed one is your primary address. The last confirmed address cannot be removed. Your primary confirmed address is the one the products you reach are told.
Your profile. A display name and, if you like, a link to a picture. The products you reach are told your display name, and those that ask for your profile also the link.
Your credentials are yours to keep. Do not share them, and tell us at contact@gplatform.org if you think somebody else has them. You are responsible for what is done under your account, as the general terms set out.
The ways in
- A password and an authenticator code, entered together in one step. Ten recovery codes stand in for the authenticator, each once. When you confirm a new authenticator, ten new codes replace the old ones.
- A one-time code by email, for an account without a password: six characters, valid for ten minutes. Your second factor still applies.
- A passkey, which is both factors at once. A passkey is bound to
sso.gplatform.org, so it opens the console there and nothing else; products send you to the console to use it. - A sign-in provider (see the next section).
Ten wrong attempts in a row pause sign-in for 15 minutes. A new letter with a link or a code can be asked for once every 60 seconds.
An organisation you belong to may require a second factor, shorten how long a sign-in lasts, or set how often you have to prove yourself again (see "Organisations and teams").
How often a product asks you again. Each product applies one of three modes: it accepts the sign-in you already have, it accepts it and asks for its own second factor, or it wants a complete sign-in every time. You can state a preference per product, but where one of our own products has set a mode, its setting wins over yours. The console shows which mode applies to each product and which setting produced it.
The providers you sign in through
You may sign in through Apple, Bitbucket, Discord, Facebook, GitHub, GitLab, Google, LinkedIn, Microsoft, Spotify, Twitch or X, where we have set the provider up, and through an OpenID Connect issuer configured for a product. Which providers are on offer is decided by us and, for their own sign-in pages, by our own products. You cannot add a provider yourself.
A provider sign-in resolves only through a link you made, never through an email address.
- Facebook, Spotify, Microsoft and X do not reliably check the addresses they hand out. You link them from your account settings while signed in, and sign in with them afterwards.
- With a provider whose word about a confirmed address we accept, signing in for the first time can make a new account. If a full account already holds the address the provider names, nobody is signed in: we send a letter to that address, and the provider is linked only when somebody opens it, within one hour.
- You cannot unlink the only remaining way into your account.
A provider is somebody else's service, used under its own terms. If a provider stops working, is switched off by us, or closes your account there, the link stops being a way in, and your other ways in are unaffected. Keep at least one way in that does not depend on a provider.
Sessions, and the one control that ends them
A sign-in lasts at most 12 hours, or less where an organisation you belong to has said so. Every product the session reaches is recorded beneath it. Your account lists your sessions, with the device, the country and the products each one reached, and you can end any of them or all of them. Signing out of the console signs you out of every product on that device.
The lockdown is the control for when you think your account is in somebody else's hands. It asks how far to go, and each choice includes the ones before it:
- End every session, in every product.
- Also require a new password at the next sign-in, revoke every personal access token, and cancel any outstanding password reset and sign-in code.
- Also suspend the account until we lift the suspension at your request. While it is suspended, nobody can sign in, including you.
- Also drop every linked provider, so that the way back in is a password or your mailbox rather than whatever was taken.
How quickly it takes effect. In GPlatform SSO at once. Each of our products checks a session again at least every 60 seconds and is also told directly, so a lockdown holds there within that minute even where our notice does not reach a product. A token already issued to an application over OpenID Connect stays valid until it expires, five minutes at most. If GPlatform SSO itself cannot be reached at that moment, a product may go on serving read-only pages to a session it had already checked for up to five minutes beyond that minute.
A lockdown leaves a support access you have granted in place and tells you so on its receipt (see "Support access").
Organisations and teams
Organisations. Anyone with a full account may create an organisation, unless a rule of an organisation or enterprise they belong to forbids it. Its creator is its owner. An organisation has exactly one owner, and ownership changes only by being handed to another member. Members hold one of five roles: owner, admin, member, billing and auditor.
Invitations are addressed to one email address, work once and are valid for seven days. An invitation is accepted with the account that holds the invited address, with a new account made for that address, or with the account you are signed in to, which then gains the invited address as a confirmed address.
Teams say who belongs together inside an organisation. They do not say what anybody may do.
Rules. An organisation, and an enterprise above it, may require a second factor, forbid creating organisations, set how often people must prove themselves again, and shorten how long a sign-in lasts. A rule only ever tightens: a narrower scope can make a rule stricter and never looser.
Closing an organisation is for its owner alone, confirmed by typing its short name. It removes every access grant, membership, team and invitation at once and tells the products concerned; its service accounts stop working. The organisation's record stays, marked closed, so that the record of what happened in it stays readable.
Belonging to an organisation does not make your account the organisation's. It cannot change your credentials or close your account. The one exception is an enterprise that manages its people's accounts (see "Enterprises").
An organisation's own people. For what an organisation records about its people in GPlatform SSO (members, roles, teams, invitations, access grants and rules), the organisation decides, and we process it on its behalf under the processing annex. An organisation that invites people or grants them access is responsible for being entitled to do so.
Access to products, and roles
An owner or admin grants a person, a team or the whole organisation a product and a role inside it. The roles are the ones the product itself publishes. GPlatform SSO stores the role and tells the product; what the role permits is the product's decision, under its own terms.
Roles can be bundled into named sets an organisation or enterprise defines, and assigned at once.
Leaving a product. You can leave a product yourself. The access granted to you by name ends, and your sessions in that product end; your sign-in elsewhere continues. Access you hold through your organisation or team stays, because it is the organisation's setting. Your account in that product is kept, so that the product goes on recognising you if access is granted back. What you made inside the product is not deleted by leaving; ask the product for that.
Service accounts let an organisation's or an enterprise's machines reach a product as themselves. Their tokens are shown once, always expire (after 90 days unless another date is chosen, after one year at most), and a rotation keeps the old token working for up to 30 days. A service account reaches only what its owner's grants allow, and can be narrowed further.
Personal access tokens let you act as yourself from outside a browser. They follow the same expiry rules, never reach further than you do, end when you close your account, and are revoked by a lockdown from its second step.
Enterprises
An enterprise groups organisations under one company. We set one up for a customer on request.
Domains. An enterprise may claim a domain and prove it: with a file on its web server, which lets new accounts on that domain be made as the enterprise's own, or with a DNS record, which also covers accounts that already exist. We check outstanding claims every 15 minutes. A claim covers exactly the domain named, not its subdomains. A claim on a free mail provider's domain is refused.
An enterprise that manages its people's accounts may, beyond the rules every organisation can set, force a password reset, manage or remove a second factor, close an account, and refuse self-registration on its claimed domain. It may do so only with a proven domain, and only at enterprise level.
If you confirm an address on a domain an enterprise has claimed and proven, that enterprise is told that an address on its domain was confirmed. An account that already exists comes under an enterprise's management only after you have been told and have had the chance to refuse.
Applications that sign people in through it
Every application is enrolled by us at one of three tiers, and the tier decides what it may do:
- Our own products may create accounts, sign people up and in on their own pages, configure their own providers, set the mode that outranks your preference, and be told your organisations and which other products you use.
- Software we run but did not write, such as a status page, may sign people in and ask who they are, including their organisations. It creates nobody, and is told which other products you use only where we have allowed it.
- Somebody else's software, including an organisation's own applications, is an OpenID Connect client and nothing more. It may be told your name, your address and your organisations if it asks for them, and is never told which other products you use.
Every application knows you by an identifier of its own, different in every application. It is told your display name and your primary confirmed address when it asks for them, so it does not stop two applications recognising you as the same person; what it ensures is that joining or moving accounts never changes what an application has already recorded.
Before an application learns who you are over OpenID Connect, you are asked. A consent screen shows which kind of application it is and what it asks for, and an application that later asks for more asks again. An account made inside a product is not asked when it signs in to that same product.
On one of our products' own sign-in pages, the password you type passes through that product's server on its way to GPlatform SSO.
An application you sign in to is responsible for what it does with what it is told, under its own terms and privacy notice. We may suspend an application's enrolment, which stops it signing anybody in.
Support access
Our support can act as you only with your consent. You grant it from your account, for a reason you are shown, for at most seven days. Within that time support may open a session as you; you can withdraw the consent at any time, which ends every session opened under it. Each product is told when a session is support acting as you. After every such session you are told by email, and every act inside it is recorded as support acting as you.
No member of our staff can read your password, your recovery codes or a product's secret, and no staff role can sign in as you without your consent.
Joining two accounts
When the same confirmed address is on two accounts, for example an account made inside a product and your full account, we offer by email, to that address, to join them. Nothing is joined unless somebody accepts the offer, from that mailbox, with the link it carries, within one hour of the letter.
When two accounts are joined, the account that remains keeps its own password, second factor and passkeys; the other account's are destroyed, together with its sessions, and its memberships, teams and linked providers move across. Every product goes on knowing you by the identifier it already had.
Closing your account
You can close your account yourself, confirmed by typing your primary address. You cannot close it while you own an organisation that is not closed: hand the organisation to somebody else or close it first.
Closing ends every session and tells every product you reached. Your memberships, the access granted to you by name, your linked providers, passkeys, password, second factor and recovery codes are removed, and your addresses become free to use again. A closed account cannot be reopened; registering again makes a new one. What you made inside each product is not deleted by closing your account; ask each product for that under its own terms.
Your account data is kept for 12 months after the account ends and then erased, leaving only the account's identifier. The details are in the privacy notice.
Restrictions, and challenging them
Because GPlatform SSO is the way into every product, an account suspended or ended here can sign in to none of them. We may restrict or end an account, or an application's enrolment, on the grounds and in the way the general terms set out: with a statement of reasons, and, before we suspend or end an account, with notice and the chance to respond, except in the cases the general terms name. A compromised account is one of them: we may then force a lockdown or a password reset first and tell you straight after.
A disabled account cannot be used again, by you or by us.
You can challenge any restriction by writing to contact@gplatform.org. A person looks at it again and answers with reasons. The courts remain open to you.
Your content, your account and these clauses
The general terms carry these clauses in full. This is how they apply in GPlatform SSO.
The content the licence covers here is what you enter into GPlatform SSO: your display name and the link to your picture, the names you give organisations, teams, role sets, service accounts, tokens and passkeys, the invitations you send, and the domains you claim. You keep all rights in it. We use it only to run GPlatform SSO: to show it to you and to the people in your organisations, and to tell the products you reach what they need to sign you in.
Who may receive it, for that purpose only: the providers who run GPlatform SSO for us (hosting, our mail server, backups and error reporting) and our other products where it is shown or used for the same purpose, which means the products you reach being told your name and your organisations; a successor of the business under the transfer clause; and companies affiliated with Gelhaus Solutions. Nobody receives a licence to your content for their own purposes. Somebody else's application receives only what you agree to on its consent screen, which is your choice and not a licence from us.
Permanent records: there are none in GPlatform SSO. Nothing you enter here is published.
Moving accounts onto GPlatform SSO. Our products move their sign-in onto GPlatform SSO one at a time; GOpenCSR, GOpenCDR, GOpenCNR, GAdvisory and GPlatform Control are among them, and each product's terms say so. Each move follows the general terms' clause on moving accounts: we email you at least 30 days in advance and say what moves, we move only what is needed to sign you in and to keep what you hold, and if signing in becomes materially harder you may end the contract free of charge within 30 days. The notice names what moves: your address and whether it was confirmed, your password hash, your display name and picture, your linked providers where GPlatform SSO offers the same provider, and, for a product whose organisations move as well, those organisations. Passkeys cannot move, because a passkey answers only the domain it was made for, and are set up once more; the notice says what else has to be set up again. The product goes on knowing you by the identifier it already had. A product that has its own terms for the move, such as GOpenCSR's sign-in transition terms, applies them as well.
GPlatform SSO is free of charge. An account, organisations, teams and access grants cost nothing; what a product charges for is bought in that product, under its terms. So if you have not accepted materially changed terms six weeks after we told you of them, your account is restricted until you accept, as the general terms set out: you can still sign in, including to every product you use, read what is here, get a copy of your data, exercise your data protection rights, close your account and accept, and nothing else. A product you pay for is never restricted by this; it follows its own terms. Liability for what is given away free of charge is limited to intent and gross negligence (Section 521 BGB).
Availability
No service level is promised. Every product that signs people in through GPlatform SSO depends on it: while it cannot be reached, nobody can sign in to them, and sessions a product had already checked keep working only as described under "Sessions, and the one control that ends them". Everything else on availability, warranty and liability is in the general terms.
Changes
These terms change through the process the general terms set out. Every version is kept in the document archive.