Operate
Application authentication
Protect a published application
A space can remain public, accept any registered Fork account, or require a named organization/project permission. Fork enforces the selected policy at the edge before protected application requests reach the guest runtime.
Browser pages receive a signed application session rather than control-plane credentials. API routes can require the same protection and return JSON authentication errors instead of a login document.
Keep application policy in the backend
Fork authentication can establish who the visitor is and whether they may enter the application. Your backend still decides which records and actions that person may use. Map the verified subject to a local account and apply the app’s own role model on every sensitive route.
Brand the sign-in flow
Space administrators can configure supported sign-in copy and visual branding from the project control panel’s white-labeling settings. Branding changes presentation; it does not weaken the configured access policy.