Identity standards
How BLACKDARK handles accounts, sessions, and privileged access — public summary for visitors.
Public summary for visitors — not a credential export. Sign in for account-specific settings.
Architecture
- product · BLACKDARK Trust OS
- primary_authenticator · email
- login_methods · ['email_password', 'google_oauth', 'github_oauth']
- phone_auth · False
- username · {'login': False, 'public_handle': True, 'pattern': '^[a-z][a-z0-9_]{2,23}$'}
- password_policy · {'min_length': 10, 'max_length': 128, 'block_common': True, 'hash': 'pbkdf2_sha256'}
- email_verification · True
- password_reset · True
- mfa · totp_optional
- avatar · {'default': 'initials_svg', 'upload': True, 'max_bytes': 2097152}
- oauth · {'enabled': True, 'providers': {'google': True, 'github': False}, 'google_signin': {'state': 'CONFIGURED', 'client_id': '732766454209-ckedigkdgb124mqr9mn61fd176l71t28.apps.googleusercontent.com'}, 'callback_path': '/api/auth/oauth/{provider}/callback', 'start_path': '/api/auth/oauth/{provider}/start', 'note': 'Set OAUTH_GOOGLE_CLIENT_ID/SECRET and/or OAUTH_GITHUB_CLIENT_ID/SECRET plus APP_BASE_URL to enable social login.'}
- profile_fields · ['email', 'display_name', 'username', 'avatar', 'ui_lang', 'ux_mode', 'timezone', 'telegram_chat_id', 'tier', 'mfa', 'email_verified']
- standards · ['NIST SP 800-63B (password length + blocked commons)', 'OWASP ASVS session / recovery', 'OAuth 2.0 state CSRF', 'GDPR export/erase (existing privacy routes)']
- billing_note · USD self-serve via hosted PSP — card data never stored here.
Anti-Hype · Not financial advice · Verify claims on the Public Accuracy Ledger.