tool si.session.sign_in.
Nothing, or the tenant to sign in to: the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller.
Figure 1si.session.sign_inspecified
the way the browser was opened, then the caller as a view once the code came back; the refresh token goes to the keychain and never to the caller. The call needs the read grant at the user rung.
- input
- SignInInput
- result
- a card whose body is Caller
- read-only
- yes
- destructive
- no
- card address
ui://scale-intelligence/cards/Caller- HTTP route
/v1/session/sign_in
| field | type | required | note |
|---|---|---|---|
tenant | id | no | |
token | text | no | an access token the identity provider issued, checked six ways at the face; never logged |
Claims#
| claim | state | route or tool |
|---|---|---|
| The MCP server declares si.session.sign_in at contract 0476e35e6e275db5. | target | si.session.sign_in |