Skip to content

Foundation & Authentication User Manual

Module: M00 Foundation & Access Control

Product: ebosAi AMP
Classification: Public / End-User Documentation
Version: 2.0


1. Authentication Architecture Overview

The ebosAi AMP platform provides a modern, passwordless authentication architecture. The system never stores raw user passwords locally, eliminating credential stuffing vulnerabilities and providing a seamless login experience across devices.

sequenceDiagram
    autonumber
    actor User as Partner / User
    participant Web as Portal Frontend
    participant API as Backend Auth Service
    participant Mail as Email Gateway

    alt Standard Login (Marketplace SSO)
        User->>Web: Click "Sign in with EBOS SSO"
        Web->>API: Exchange SSO Token
        API-->>Web: Set httpOnly Session Cookie
        Web-->>User: Redirect to Dashboard
    else Fallback Login (OTP Code)
        User->>Web: Enter Email at /partners/login
        Web->>API: Request OTP Code
        API->>Mail: Send 6-Digit Code
        Mail-->>User: Receive OTP Email (10m expiry)
        User->>Web: Enter OTP Code
        Web->>API: Verify Code
        API-->>Web: Set httpOnly Session Cookie
        Web-->>User: Grant Dashboard Access
    end

2. Step-by-Step Login Instructions

Option 1: EBOS Marketplace Single Sign-On (SSO) — Primary Method

If your account is linked through the central EBOS Marketplace: 1. Navigate to the login page (/login or /admin/login). 2. Click the Sign in with EBOS Marketplace SSO button. 3. You will be authenticated against your central account credentials. 4. Upon successful verification, you will be redirected immediately to your active workspace.

Option 2: One-Time Password (OTP) — Partner Portal & Emergency Fallback

For partners and creators logging into the self-service portal: 1. Navigate to /partners/login. 2. Enter your registered email address. 3. Click Send OTP Code. 4. Check your email inbox for a message titled "Your ebosAi AMP Verification Code". 5. Enter the 6-digit numeric code on the verification screen. 6. Click Verify & Login. You will be securely logged in and redirected to your dashboard.

[!IMPORTANT] - Code Lifetime: OTP codes are strictly valid for 10 minutes from the moment of generation. - Security Lockout: To prevent brute-force attacks, accounts are locked out for 30 minutes after 3 consecutive failed verification attempts or 3 OTP generation requests within a single hour.


  • Stateless Tokens: Authentication sessions are maintained via encrypted httpOnly, Secure, SameSite=Strict browser cookies (amp_partner_token or amp_admin_token).
  • XSS Immunity: Session tokens cannot be accessed or modified by JavaScript in the browser.
  • Session Expiry: Sessions automatically expire after 24 hours of inactivity or upon clicking Logout in the navigation header.

4. Troubleshooting Login Issues

Problem Potential Cause Solution
Didn't receive the OTP code Spam filter or incorrect email Check your Spam/Junk folder. Ensure the email address entered matches your approved partner email.
"Invalid or Expired OTP" Code entered after 10 minutes or typo Request a fresh OTP code and enter it within 10 minutes.
"Too Many Requests" (429) Rate limit triggered Wait 30 minutes before requesting a new code.
"Account Suspended" Administrative action by merchant Contact your affiliate program administrator to check account status.