{
  "schemaVersion": "dsti.public-authentication-explanation.v1",
  "locale": "en-GB",
  "public": true,
  "helpUrl": "https://application.dsti.school/mcp/help",
  "jsonUrl": "https://application.dsti.school/mcp/authentication.json",
  "authenticationHostname": "auth.application.dsti.school",
  "providerPresentation": {
    "primary": "Google",
    "fallback": "native Cognito email and password",
    "fallbackClearlyAvailable": true
  },
  "applicationOwnershipAuthority": "normalised verified email",
  "providerIdentityAuthority": "provider issuer and subject",
  "automaticMergeFromEmailEqualityAlone": false,
  "wording": {
    "pageTitle": "Connect ChatGPT to your DSTI application safely",
    "pageLead": "Sign in to let ChatGPT use only the DSTI application permissions you approve. Your application remains governed by the DSTI backend and remains available through the secure Web portal.",
    "whySignIn": "You need to sign in so DSTI can associate this ChatGPT connection with your verified email address, protect your application details and let you safely resume, update or submit your own application.",
    "mailboxInstruction": "Use the same email address that you use, or intend to use, for your DSTI application. If you already started an application with another address, continue in the secure DSTI Application Web Portal and use its recovery process instead of trying to claim it through chat.",
    "providerDisclosure": "Google is the primary sign-in choice. The native Cognito email-and-password option remains clearly available as a fallback. Sign-in is handled through Amazon Cognito, an AWS identity service operated for DSTI.",
    "credentialIsolation": "Your Cognito password, Google password, verification code and recovery secret are entered only on the relevant Cognito or Google page. They are never shared with ChatGPT or the DSTI Application MCP.",
    "permissionExplanation": "ChatGPT receives only the OAuth permissions you approve for the DSTI application service. Read, update and submission permissions remain distinct and are rechecked by the DSTI backend for every operation.",
    "linkingExplanation": "If a native Cognito account already uses the same verified mailbox, you must independently authenticate both that account and Google before they can be linked. DSTI will never merge accounts from email equality alone.",
    "recoveryExplanation": "If sign-in, account matching or ownership is unclear, no application is linked automatically. Use the secure DSTI Application Web Portal or contact DSTI support for recovery.",
    "providerResponsibility": "DSTI governs application ownership and authorisation. Amazon Cognito or Google authenticates the account; ChatGPT invokes only the approved DSTI application operations.",
    "poweredByWording": "Authentication is powered and secured by Amazon Cognito. Your Google credentials, when Google sign-in is used, remain with Google."
  }
}
