The four auth postures What stands between a landing-page card and its terminal under each auth.method: none makes the card the door, nginx stamping that user's secret; token hands out a login URL and nginx stamps nothing; password and oidc put a login page in front, the authentication service checking it before nginx stamps. Behind every posture the terminal itself still checks one credential of its own on every request. FRONT DOOR · NGINX BEHIND IT · THE TERMINAL ITSELF none a card is the door nginx stamps the user's secret token a login URL, once the default · nginx stamps nothing password a login page auth service · then nginx stamps oidc a login page your SSO · then nginx stamps every terminal checks one credential of its own, every request the operator secret nginx stamps, or the cookie a login URL traded it for