{"model":"brokered-sso","identity_provider":"Microsoft Entra External ID","flow":["User opens a product alias or /login with an app target.","Broker validates target and safe return path.","Customer signs in or registers through External ID.","Broker resolves WHMCS/customer entitlement where required.","Broker issues a target-specific SSO assertion or denies access."],"public_endpoints":[{"method":"GET","path":"/","purpose":"Default sign-in page"},{"method":"GET","path":"/login","purpose":"Start sign-in for a supported target"},{"method":"POST","path":"/login","purpose":"Continue sign-in form submission"},{"method":"GET","path":"/reset","purpose":"Password recovery handoff"},{"method":"POST","path":"/reset","purpose":"Start password recovery handoff"},{"method":"GET|POST","path":"/auth/entra/callback","purpose":"External ID callback"}]}