
Account protection
Security activity.
Review OAuth, passkeys, 2FA, sessions, login risk, recovery, and admin security controls from one protected workspace.
| Event | Surface | Public-safe rule |
|---|---|---|
| auth.oauth.google.login_completed | Login/signup | Creates only a normal DigiShelf session after verified Google identity |
| auth.oauth.google.signup_completed | Login/signup | New accounts require Google email_verified before session creation |
| auth.oauth.google.link_completed | Account security | No provider token in public payload |
| auth.passkey.registered | Account security | Public key hash is internal only |
| auth.2fa.enabled | Account security | Raw TOTP secret is not displayed |
| auth.admin.impersonation.request_blocked | Admin security | Super admin plus step-up and reason required |