name: Stytch description: >- Vocabulary of key terms, concepts, and objects used across the Stytch authentication platform. Covers passwordless authentication, session management, B2B multi-tenancy, and identity infrastructure. version: "1.1" created: "2026-05-02" modified: "2026-05-22" tags: - Authentication - Identity - Passwordless - B2B terms: - term: Magic Link definition: >- An email containing a one-click authentication link that logs in or signs up a user without requiring a password. The link contains a time-limited token and redirects to the application after clicking. Expires after a configurable duration. category: Authentication Method tags: - Passwordless - Email - term: OTP (One-Time Passcode) definition: >- A short numeric code (typically 6 digits) sent to a user via SMS, email, or WhatsApp. Valid for a single use within a short time window. Stytch supports SMS OTP, email OTP, and WhatsApp OTP. category: Authentication Method tags: - Passwordless - OTP - term: Session Token definition: >- An opaque string returned after successful authentication. Used in server-side requests to identify the authenticated user. Pairs with a Session JWT for client-side use. category: Session Management tags: - Sessions - Security - term: Session JWT definition: >- A JSON Web Token (JWT) representing the user's session. Contains claims about the user, organization (B2B), and authentication factors. Can be validated locally without a network call to Stytch. category: Session Management tags: - Sessions - JWT - term: User definition: >- A Stytch Consumer user record identified by user_id (prefix: user-). Stores email addresses, phone numbers, name, and metadata. Created automatically on first login. category: Core Object tags: - Consumer - Identity - term: Member definition: >- A Stytch B2B user within an Organization. Identified by member_id (prefix: member-). Has roles, a status (active, invited, deleted), and belongs to exactly one organization. category: Core Object (B2B) tags: - B2B - Identity - term: Organization definition: >- A B2B tenant in Stytch. Represents a customer company or workspace. Contains members, SSO configurations, and access policies. Identified by organization_id (prefix: organization-). category: Core Object (B2B) tags: - B2B - Multi-Tenant - term: SSO (Single Sign-On) definition: >- Authentication through an enterprise identity provider (IdP). Stytch B2B supports SAML 2.0 and OIDC protocols. Connections are configured per organization and can be used for just-in-time (JIT) member provisioning. category: Authentication Method tags: - SSO - SAML - OIDC - B2B - term: TOTP (Time-Based One-Time Password) definition: >- An authenticator app-based second factor. Users register a TOTP device (Google Authenticator, Authy, etc.) and use 6-digit rotating codes to authenticate. Stytch Consumer only. category: Authentication Method tags: - TOTP - MFA - term: WebAuthn definition: >- Browser-native biometric and hardware key authentication (passkeys, fingerprint, Face ID, hardware security keys). Stytch implements the W3C WebAuthn standard for phishing-resistant authentication. category: Authentication Method tags: - WebAuthn - Biometrics - Passkeys - term: OAuth definition: >- Social login via OAuth 2.0 providers (Google, Apple, Microsoft, GitHub, etc.). Users click a provider button and authorize access. Stytch handles the OAuth flow and creates or links a user record. category: Authentication Method tags: - OAuth - Social Login - term: Project ID definition: >- The public identifier for a Stytch project. Used as the username in HTTP Basic authentication. Format: project-live-xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx (live) or project-test-xxx (test). category: API Concept tags: - API Keys - Authentication - term: Secret definition: >- The private API key for a Stytch project. Used as the password in HTTP Basic authentication. Never expose in client-side code. Must be rotated if compromised. category: API Concept tags: - API Keys - Security - term: JIT Provisioning definition: >- Just-In-Time automatic member creation when a user authenticates via SSO for the first time. Configurable per organization. Avoids manual invitation workflows. category: B2B Feature tags: - SSO - Provisioning - B2B - term: Intermediate Session Token definition: >- A short-lived token issued during the B2B organization discovery flow when a user has authenticated but hasn't yet selected which organization to log into. category: B2B Feature tags: - B2B - Discovery - Sessions - term: Authentication Factor definition: >- A record of how a user authenticated in the current session. Stored in the session object. Includes the method (magic_link, otp, sso), the factor type, and timestamp. Multi-factor sessions include multiple factors. category: Session Concept tags: - MFA - Sessions - term: Connected App definition: >- An OAuth 2.0 / OIDC client registered under a Stytch project so an external tool — a third-party integration, desktop app, AI agent, or MCP server — can request scoped, user-consented access to the product Stytch protects. Connected Apps make the Stytch-secured product itself act as an Authorization Server. category: Authorization tags: - Connected Apps - OAuth - OIDC - MCP - AI Agents - term: MCP Server Client definition: >- A specific kind of Connected App — a Model Context Protocol server registered as a public OAuth client (with PKCE) so AI agents can obtain scoped tokens to call your tools. category: Authorization tags: - MCP - AI Agents - Connected Apps - term: M2M Client definition: >- A machine-to-machine OAuth 2.0 client. Holds a client_id + client_secret pair and a set of scopes; exchanges them for short-lived JWT access tokens via the client_credentials grant. Used for service-to-service auth and headless automation. category: Authorization tags: - M2M - OAuth - Client Credentials - term: Discovery Flow definition: >- The B2B authentication path where a user first authenticates (via Magic Link, OAuth, or SSO) and is then offered the list of organizations they may join. Concludes by exchanging an intermediate session token for an org-scoped session. category: B2B Feature tags: - B2B - Discovery - Multi-Tenant - term: SCIM Connection definition: >- A per-organization SCIM 2.0 endpoint Stytch exposes so an enterprise customer's IdP can push directory updates — create / update / disable members and groups. Complements SAML / OIDC SSO with automated provisioning and deprovisioning. category: B2B Feature tags: - SCIM - Provisioning - B2B - term: Device Fingerprint definition: >- A telemetry signal collected by Stytch's DFP browser / mobile SDK. The server-side fingerprint lookup turns a telemetry_id into a verdict (allow / challenge / block) plus a visitor_id and verdict reasons used for adaptive MFA. category: Fraud & Risk tags: - Fraud - Device Fingerprinting - Bot Detection - term: Verdict Action definition: >- The Stytch fraud system's recommended action for a request — typically allow, challenge, or block. Drives adaptive MFA / step-up logic and Connected Apps consent decisions. category: Fraud & Risk tags: - Fraud - Adaptive MFA - term: Impersonation definition: >- A controlled flow that lets staff act as a User or Member to debug or support a customer account. Impersonation sessions are tagged distinctly so they can be audited and revoked separately from normal sessions. category: Operations tags: - Support - Auditing - term: Management API definition: >- Stytch's programmatic configuration surface (host management.stytch.com) for projects, environments, secrets, RBAC policies, JWT templates, email templates, event log streaming, public tokens, and trusted token profiles. Separate from the runtime auth API at api.stytch.com. category: API Concept tags: - Management - Configuration