DACS
Durable organizational memory and agent orchestration. You will be sent to the identity provider and returned straight to your galaxy.
Use Sign in as someone else on a machine both owners share. Without it the identity provider silently returns whoever signed in last, and you get a working session for the wrong account.
Paste the single-use token the inviting owner gave you. Sign in as the person the invitation was addressed to — not as whoever sent it.
The token is sent in the address bar, so it is recorded in this browser's history. It is single-use and is only spent once the whole sign-in succeeds.
Only for a deployment that has never had an owner. Needs the bootstrap token from the environment the API was started with.
If the identity provider was rebuilt or migrated it may have issued you a new internal identifier, which DACS treats as a different person on purpose. Active owners can authorize a deliberate operator recovery for your existing account.
Refusals here are one uniform answer by design: a replayed sign-in, an expired token, an address that does not match the invitation and an organization that already has an owner all look identical, so that an anonymous caller learns nothing by trying. The server log names the cause.