Authorizes the next matching federated assertion to bind this pre-existing local
account to the asserting identity, within a bounded window.
The administrator supplies the provider and the email claim they expect that
provider to assert — never the provider's internal subject identifier, which they
have no way to know. The platform learns the subject at the first matching assertion
and keys the binding on it from then on.
The window defaults to 72 hours and is capped at 168. A request above the cap is
refused, never clamped: a silent clamp would tell the administrator they received
a window they did not receive, and the out-of-band coordination this flow depends on
would be planned around a deadline that has already passed.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||