Authentication
Avanora keeps identities separate across planes. Operator sessions power Control, tenant sessions power Core, and end-customer experiences default to magic links unless a module introduces its own auth.
Tenant sessions
Admin users authenticate to Core with password plus optional TOTP. Every request carries tenant context derived from the session so cross-tenant access remains impossible even if a route parameter is tampered with.
Connect API
Integrations use scoped API keys with explicit module permissions. Rotate keys from the Connect console and verify webhook signatures with the per-endpoint secret recorded in Control.