Email one-time-code identity
One-time codes are hashed with a server secret, expire after ten minutes, are single-use, and have an attempt cap. A successful cast uses one verified email address for one campaign uniqueness boundary.
A result is useful only when its identity source, counting rule, response obligation, and limits are stated plainly. This page separates current controls from setup gates, product Direction, and claims player.vote does not make.
These controls run in the current product. They do not depend on a future enterprise programme.
The complete decision path uses the same identity, counting, reveal, response, and export boundaries.
One-time codes are hashed with a server secret, expire after ten minutes, are single-use, and have an attempt cap. A successful cast uses one verified email address for one campaign uniqueness boundary.
Options, method, identity mode, and eligibility cannot change underneath participants after the decision opens.
Scores remain withheld while a decision is open by default, while turnout can remain visible.
A host can restrict a campaign to the declared email set and can attach groups for result breakdowns.
The cap check, participant link, voter identity, and ballot write share the same commit boundary. Invalid ballot data does not consume a valid partner token.
Append-only lifecycle events, CSV export, the company response, and the recorded outcome remain attached to the original contract.
These are not Direction claims. Each path exists, but a host or operator must complete the stated setup.
An approved backend can mint a five-minute, campaign-bound voter token for one stable partner subject. Issuer approval remains manual because the assertion label is a claim about that issuer.
A participant can return across client relationships. Each client sees only its own scoped relationship, not the global participant identifier.
Signed webhook delivery, retries, replay, and rotation exist. Production delivery requires a signing root and exact hostname allowlist.
Show-once API keys use exact scopes for campaigns, participant relationships, grants, and voter-token minting. Browser Origin requests are refused.
Client-bound embeds use exact registered origins, strict frame policy, a source-checked message handshake, and memory-only partner tokens. Safari and a production sibling-domain deployment are not yet verified.
The host must prove the TXT claim, point the CNAME, and wait for an active certificate before the hostname can serve the record.
Verification raises the cost of duplicate or unauthorised participation. It does not turn an identifier into a verified human.
Aliases, disposable addresses, and shared inboxes remain possible. Use an allowlist or approved partner identity when the electorate needs a stronger boundary.
player.vote binds and records the approved issuer subject. The issuer still owns its account controls and the truth of that subject.
player.vote enforces the declared electorate. It cannot prove that the host selected the right people or interpreted the evidence well.
The scoped embed has been exercised in Chrome and Firefox with third-party cookies blocked. Safari and a production sibling-domain deployment are not yet verified.
A management route is an authority boundary, not a convenience link.
Hosts can export results, ballots, group breakdowns, and the audit log as CSV. Exports exclude authentication secrets and management capabilities.
Deletion revokes active access and removes decision, ballot, relationship, and host personal data under the current deletion path. Historical ballot boundaries are not rewritten to permit a second ballot.
Account-owned decisions remain available through the signed-in host workspace.
A legacy or anonymous decision relies on its campaign-scoped manage capability until the host claims it. The raw link exchanges for a scoped HttpOnly cookie and redirects to a clean URL.
The emergency management link remains sensitive. Anyone holding a still-valid capability can exercise its campaign authority.
Multi-seat roles, administrator SSO or SAML, workforce provisioning, retention policy, and broader enterprise administration are not built yet.
These statements are limits, not promises that a certification programme will arrive on a particular date.
player.vote does not claim SOC 2 certification.
player.vote does not claim ISO 27001 certification.
player.vote does not publish a public uptime or status claim because no public status page exists.
Choose the identity source, electorate, method, response, and outcome promise before participation begins.