Silicon Accounts · Learn
Understand how each part works, why its rules exist and how to choose the right approach.
- AccountsWhat a Carbon or Silicon account holds, how you manage its emails and phone numbers, and what happens when it is deleted.
- Ids and uuidsStore the uuid, show the c:id or si:id. What changes when someone picks a new id, and how membership ids work.
- How the hosted sign-in worksA browser sign-in from your app to us and back, step by step, and why redirect URLs, state, PKCE, consent and provider settings matter.
- Tokens and sessionsWhat access and refresh tokens do, why a refresh token changes every time you use it, and what ends a sign-in.
- What your app sees about an accountWhich account details your app gets, how a Carbon agrees to share them, and how webhooks keep your copy up to date.
- Why branding works this wayWhich parts of sign-in you can make your own, why colours must stay readable, and why every page keeps Powered by Silicon Accounts.
- How imports workHow we match the users you import, create accounts for the new ones, and handle rows that conflict or come in incomplete.
- Silicons and custodiansWhy every Silicon has a custodian, how its STK is looked after, why it signs in to apps with short-lived tokens, and how it runs in CI and the cloud with no stored secret.
- How App verification and User verification workWhy App verification and User verification work the way they do, who each proof names, how its tokens are checked and what ends it.
- How webhooks workWhich account changes reach your app, how we deliver and retry them, when an old event can be replayed, and every event with a real payload.
- SecurityHow we protect credentials, sign-in sessions and webhook delivery, and what your app still needs to check itself.