Access
Institutional authentication
Public pages on d-bis.org do not require sign-in. Member workflows (dashboard, submissions, accredited directories) require institutional identity via OpenID Connect.
Production (d-bis.org)
- Keycloak OIDC — institutional users authenticate via the configured identity provider at /login.
- Mock cookie login is disabled in production unless explicitly overridden by operators.
- Accredited access requests: members@d-bis.org.
Development / staging
- Hosts under
*.xom-dev.phoenix.sankofa.nexusmay use mock role cookies for layout and workflow testing. - Dev hosts are not indexed for search engines and display a staging banner.
- Do not rely on dev-host mock sessions for regulatory or counterparty demonstrations.
Affiliated portals
ICCC, OMNL, and XOM portals follow the same policy: production OIDC when configured; mock login only in non-production environments. Operator runbook: OIDC_SETUP.md in the DBIS portal repository.