Authentication & sessions
The WorkOS/AuthKit session model, server-owned identity, and how roles map to what a caller can see.
Contract unavailable
This docs section is listed in the spine so readers can see the planned boundary, but it is not a published integration contract yet. Do not build against this page as a complete API, MCP, auth, mirror, no-leak, projection, or route-boundary reference.
AuthKit sessions are live in the app; the session and roles doc is not started.
The section is scoped for the spine and the behavior it describes is live in the product, but no public doc content exists yet.
What lives where
The ownership boundary this docs site depends on. If a fact is on the wrong surface, it drifts: docs hold contracts, the homepage holds the product story, Studio holds the creator's private workspace copy.
Routing rule: a sentence that promises behavior to an integrator lives in Docs. A sentence that sells the product lives on the Homepage. A sentence that operates one creator's twinlet lives in Studio. Docs link to Studio for actions like key issuance — they never duplicate its copy.