Ops Suite sign-in

Staff realm. In production this is AWS Cognito SSO + MFA (D31). On a dev box the in-api dev issuer mints the session — pick a synthetic principal, then enter the one-time code. A signed-in admin reads live codes at Admin → Sign-in codes (D58 test-phase concierge); the first sign-in after a fresh boot reads the code from the api log on the box (journalctl -u fleetos-api).

Staff and admin accounts are provisioned by your administrator. There is no self-service ops/admin sign-up on the web: only rider (consumer) accounts self-register — ops, admin and council accounts come from a fixed, admin-managed registry (A13 / D52).

Synthetic dev principals