Provider-backed sign-in uses authorization code with PKCE. Matari stores only a hash of its opaque browser session token, rotates CSRF protection, and does not store staff passwords.
WHY IT MATTERSAccess stays tied to an individual identity instead of an unaccountable browser session.