# Login registry — secret-free Which product login lives in which chrome-box profile, on which NetVM node, with which egress, in what auth state. This is structure only: **no passwords, no tokens, no session cookies, no OTP codes — ever.** Credential pointers at most (e.g. "human", "credential-gateway:"). The 1:1 chain: `login -> profile = node = Warp identity = veth/CDP slot = consistent egress`. Network details live in NODES.md; this file maps the human side (whose login, what for, does it work). ## Auth states | state | meaning | who moves it | |-------|---------|--------------| | `pending-identity` | profile exists, no Warp identity yet | human runs `netvm-new-identity.sh ` | | `pending-auth` | node up, nobody logged in yet | human logs in (browser or credential gateway) | | `2fa-pending` | login needs a human 2FA/OTP step | human via ethical-captcha handoff; OTP routed by email-alert | | `active` | logged in, session healthy | operator verifies; automation may proceed | | `expired` | session died | back to `pending-auth` (human) | | `retired` | login no longer used | operator tears down node, archives row | Operators never create or touch credentials. If it creates or touches a credential, it is human-only. Everything else, operators handle. ## Registry | login | product | profile/node | purpose / owner | auth state | 2FA / verify route | notes | |-------|---------|--------------|-----------------|------------|--------------------|-------| | — | — | tp | orchestrator / operator-main | pending-auth | — | first node; no product login yet | | — | — | smoke | dev test rig | pending-auth | — | dedicated test profile; muse.ai loads, no login yet | ## Known login flows ### muse.ai (recon 2026-10-03, via CDP DOM) - Homepage has "Log in" buttons (JS, no href). Click -> inline form, same URL. - "Log in or create an account" — single field: "Mobile number or email (required)" + Continue. - Phone/email OTP flow (SMS or email code). No password, no OAuth buttons. - Human completes it in one visible session; operators verify + automate after. ## Provisioning a new login (dev) 1. Operator: `chrome-box create ` (profile name = future node name). 2. Human: `netvm-new-identity.sh ` (Warp identity — credential). 3. Operator: `netvm-node-up.sh `; add rows to NODES.md and here (`pending-identity` -> `pending-auth`). 4. Human: authenticate the login in the profile's browser (`netvm-chrome.sh ` visible, or credential-gateway injection). Row -> `active`. 5. Operator: verify with `netvm-exec.sh -- ...` / CDP; keep the session warm. On 2FA: ethical-captcha handoff, OTP via email-alert.