Knowledge base
Scopes and claims
openid — stable sub (required) profile — display-safe name only (never email) rsi.profile — verified RSI handle (alias: rsi, kept for SENTRY-Web) orgs.primary — main organization only orgs.public — public org memberships (alias: orgs). Hidden/redacted stay placeholders orgs — legacy alias of orgs.public (same claims) rsi:enlisted — public RSI Enlisted date from SENTRY (cached) discord — Discord snowflake only; also requires Account Discover=on for userinfo and reverse lookup. Never in the ID token. No roles scope (Discord role IDs are not dumped) email — real verified email only if the user ticks it; synthetic @users.navcom.local is never shared These names match scopes_supported on /.well-known/openid-configuration. If a required binding is missing, Allow is blocked. No half-identity is issued. Recommended community default: required openid rsi.profile; optional orgs.primary orgs.public email discord rsi:enlisted. Discover toggle (Account → Status): default off. Reverse Discord↔RSI lookups only succeed when the subject opted in AND the token has rsi.profile+discord.