Choose the right path
Top-level sections now have their own routes, breadcrumbs, and sidebar placement so product pages can link to the exact destination.
Implemented surface and public boundaries
Public docs distinguish generally available, delivered, Preview, and Roadmap capabilities. “Delivered” does not silently become protocol conformance, certification, or universal production readiness.
| Area | Status | Public boundary |
|---|---|---|
| Authorization Code + PKCE | GA | Default interactive client path. |
| Governed application lifecycle | Delivered | Qualified profiles cover publisher review, revisions/environments, consent, installation, assignment, admission, and removal; production/conformance remain separate. |
| Organization branding | Preview | Versioned text, color, safe-link, preview, publish and rollback on the shared NexinID host; no custom authentication-domain claim. |
| Progressive authentication | Preview | Passkey-first sign-in with policy-governed TOTP fallback and separate recovery. |
| OAuth Device Authorization | GA when enabled | Requires an enabled endpoint and a provisioned device-flow client. |
| Device activation and offline leases | GA (bounded) | Seat-bound activation, approval, heartbeat, renew, transfer, revoke, and audit diagnostics. |
| IoT zero-touch bootstrap | Roadmap | No current FDO, BRSKI, or generic manufacturer zero-touch support claim. |
Diligence material that stays public-safe
The docs summarize the implemented platform without linking readers to private engineering notes. Use them for deployment posture, key handling, tenant isolation, audit visibility, and production-readiness expectations.
Authoring model
Docs remain in Razor Pages for now because the site already ships that stack and the current content is componentized around shared partials. New deep-dive content can slot into route-level pages or extracted partials; a markdown docs stack is worth revisiting only when non-engineering authors need regular direct edits.