Foundation & Authentication User Manual¶
Module: M00 Foundation & Access Control¶
Product: ebosAi AMP
Classification: Public / End-User Documentation
Version: 2.0
1. Authentication Architecture Overview¶
The ebosAi AMP platform provides a modern, passwordless authentication architecture. The system never stores raw user passwords locally, eliminating credential stuffing vulnerabilities and providing a seamless login experience across devices.
sequenceDiagram
autonumber
actor User as Partner / User
participant Web as Portal Frontend
participant API as Backend Auth Service
participant Mail as Email Gateway
alt Standard Login (Marketplace SSO)
User->>Web: Click "Sign in with EBOS SSO"
Web->>API: Exchange SSO Token
API-->>Web: Set httpOnly Session Cookie
Web-->>User: Redirect to Dashboard
else Fallback Login (OTP Code)
User->>Web: Enter Email at /partners/login
Web->>API: Request OTP Code
API->>Mail: Send 6-Digit Code
Mail-->>User: Receive OTP Email (10m expiry)
User->>Web: Enter OTP Code
Web->>API: Verify Code
API-->>Web: Set httpOnly Session Cookie
Web-->>User: Grant Dashboard Access
end
2. Step-by-Step Login Instructions¶
Option 1: EBOS Marketplace Single Sign-On (SSO) — Primary Method¶
If your account is linked through the central EBOS Marketplace:
1. Navigate to the login page (/login or /admin/login).
2. Click the Sign in with EBOS Marketplace SSO button.
3. You will be authenticated against your central account credentials.
4. Upon successful verification, you will be redirected immediately to your active workspace.
Option 2: One-Time Password (OTP) — Partner Portal & Emergency Fallback¶
For partners and creators logging into the self-service portal:
1. Navigate to /partners/login.
2. Enter your registered email address.
3. Click Send OTP Code.
4. Check your email inbox for a message titled "Your ebosAi AMP Verification Code".
5. Enter the 6-digit numeric code on the verification screen.
6. Click Verify & Login. You will be securely logged in and redirected to your dashboard.
[!IMPORTANT] - Code Lifetime: OTP codes are strictly valid for 10 minutes from the moment of generation. - Security Lockout: To prevent brute-force attacks, accounts are locked out for 30 minutes after 3 consecutive failed verification attempts or 3 OTP generation requests within a single hour.
3. Session Security & Cookie Handling¶
- Stateless Tokens: Authentication sessions are maintained via encrypted
httpOnly,Secure,SameSite=Strictbrowser cookies (amp_partner_tokenoramp_admin_token). - XSS Immunity: Session tokens cannot be accessed or modified by JavaScript in the browser.
- Session Expiry: Sessions automatically expire after 24 hours of inactivity or upon clicking Logout in the navigation header.
4. Troubleshooting Login Issues¶
| Problem | Potential Cause | Solution |
|---|---|---|
| Didn't receive the OTP code | Spam filter or incorrect email | Check your Spam/Junk folder. Ensure the email address entered matches your approved partner email. |
| "Invalid or Expired OTP" | Code entered after 10 minutes or typo | Request a fresh OTP code and enter it within 10 minutes. |
| "Too Many Requests" (429) | Rate limit triggered | Wait 30 minutes before requesting a new code. |
| "Account Suspended" | Administrative action by merchant | Contact your affiliate program administrator to check account status. |