Skip to content

Personas and bindings

Many State Cards can require the same Auth Persona. Bind the Persona on the current machine, then compatible Cards can use that local authentication capability without placing its raw value inside the ordinary portable State Card.

Common safe statuses are:

Status Meaning What to do
READY The required local binding is available. Reproduce the State Card.
AUTH_BINDING_REQUIRED No compatible local binding exists. Bind or re-authenticate the Persona.
REAUTH_REQUIRED The saved session is no longer accepted. Re-authenticate the Persona.
AUTH_ORIGIN_MISMATCH The binding cannot be used for this origin. Create a correctly scoped binding.
AUTH_POLICY_DENIED Local credential policy refused the operation. Check supported OS credential storage and project policy.

An Auth Binding is machine-local and is not transferred by an ordinary State Card share. The recipient establishes their own compatible local authentication.

Protected values explicitly retained from a captured workflow use a separate machine-local protected-value boundary. They also remain outside ordinary sharing in the current Public Beta.