Signing in
Madebook has no sign-in of its own. You use the shared Bookbag account — what that means for your password, your devices, your organizations and your notifications.
Madebook does not have a login. Every Bookbag product shares one account at sso.bookbag.ai, the way every Google product shares one account at accounts.google.com.
This is not a convenience layer over a Madebook password. Madebook has no password store any more. The sign-in, registration and password-reset endpoints still exist in the server code but are not routed — they are unreachable.
What happens when you sign in
- You open any Madebook address, or
app.madebook.ai/auth/logindirectly. - Madebook checks whether you already have a session here. If you do, it sends you straight on to where you were going.
- If you do not, the page says "Taking you to Bookbag sign-in…" and hands you to Bookbag. If the redirect somehow does not fire, a Continue link on that page does the same thing by hand.
- You sign in at Bookbag.
- Bookbag hands you back, and you land on the page you originally asked for — not on a home page. The destination travels with you the whole way as a
nextparameter.
The handover is an OpenID Connect authorization code flow with PKCE. The in-flight verifier and state travel in a sealed, encrypted cookie that expires after 10 minutes, rather than in a database table — they are worthless sixty seconds later and belong to one browser.
The pages that no longer do anything
These addresses still exist so that old links, bookmarks and "you must sign in first" redirects keep working. Each one forwards and does nothing else.
| Address | Where it takes you |
|---|---|
/auth/login |
Bookbag sign-in, carrying where you were going |
/auth/register |
sso.bookbag.ai/auth/register |
/auth/resetpassword |
sso.bookbag.ai/auth/resetpassword |
/auth/changepassword |
sso.bookbag.ai/auth/resetpassword |
/account/profile |
sso.bookbag.ai/user/profile |
/account/sessions |
sso.bookbag.ai/user/profile |
/organizations/<id>/people |
The organization's page at Bookbag account, sso.bookbag.ai/user/organizations/<id> |
/organizations/<id>/chat |
The same organization page |
/organizations/<id>/storage |
The same organization page |
/organizations/<id>/ai |
The same organization page |
The four organization addresses were Madebook's People, Chat, Storage and AI self hosted pages. Those pages are gone: people, chat, files, storage and AI settings are managed on the organization's page at Bookbag account, for every product at once.
If you are looking for your name, your password, or your signed-in devices, they are all in one place: your Bookbag account.
How long a session lasts
Your Madebook session is one row per signed-in device. Three numbers govern it:
| Idle timeout | 12 hours |
| Absolute maximum age | 30 days |
| Sliding renewal | If more than 15 minutes have passed since the session was last seen, the 12-hour window restarts. |
Expiry is enforced on the server on every request. An expired row — or one past the 30-day absolute limit — is deleted on sight.
A session is also refused, identically, when the Bookbag account is paused or blocked, when the local profile is missing, or when the profile is deactivated. All of those look the same from the browser: you are sent to sign in.
When a request arrives with an expired session, the API answers HTTP 200 with a redirect envelope rather than a 401, and the web app turns that into a sign-in redirect that preserves where you were. The message is "Your session has expired." Two other connection failures you may see instead:
- "Could not reach the Madebook API. Is it running?"
- "The API returned something that was not JSON."
Signing out
Signing out of Madebook ends the shared session at Bookbag as well, and lands you on the Bookbag sign-in page.
That is deliberate. A local sign-out on its own would bounce you through /auth/login, find the Bookbag session still alive, and sign you straight back in — which looks exactly like a sign-out button that does not work.
The reverse also holds. Ending a device's session from your Bookbag account ends its Madebook session with it: the SSO session id recorded when you signed in is checked on every request.
What lives at Bookbag and not in Madebook
This is the part worth understanding before you go looking for a settings page that is not there.
| Thing | Where |
|---|---|
| Your name and profile | Bookbag |
| Your password | Bookbag |
| Your signed-in devices | Bookbag |
| Organizations — created, named and peopled | Bookbag |
| Who is in an organization, and their role | Bookbag |
| An organization's chat, files, storage and AI settings | Bookbag |
| Your notification inbox | Bookbag, read through Madebook |
| Everything else — workspaces, repositories, missions, sessions, governance | Madebook |
Your name and picture are the account's too, and Madebook keeps no copy of them. Its own user record holds the account id and nothing else about you (plus what is Madebook's own: a job title, a timezone, the platform-admin flag). Every page that shows people asks Bookbag who those account ids are, once per request — so a name changed at Bookbag is the name on the next page load in every product, with nothing to sync and nothing that can go stale.
Madebook never stores an organization or its members. It asks Bookbag, on the server, authenticated with its app token (SSO_APP_TOKEN), and keeps the answer for a few seconds so that a page checking your role five times makes one call. Every write clears that cache for the person who made it.
That is also why there is no People row in the sidebar. Who is in the organization is the account's answer, not Madebook's, so every door to it — Manage organization ↗ on the organization's Home, Manage ↗ on Overview — opens Bookbag account in a new tab rather than a second copy here.
If Bookbag is unreachable
Reads against Bookbag never throw. A failure answers the question conservatively — no organizations, no role — so an outage narrows your access rather than widening it. You will see fewer organizations than you have, not more, and no page will grant you a permission you do not hold.
There is a 6 second timeout on each call and a 15 second cache on the answer.
Your notifications
The bell in the header reads the Bookbag inbox through Madebook's server. Marking one read, or removing one, happens at Bookbag. The "see all" link at the bottom of the panel goes to sso.bookbag.ai/user/notifications.
Alongside the shared inbox, the bell also shows Madebook's own attention items for the workspace or organization you are in, linking to that scope's Attention page.
Related
- Organizations — the tenant, and what Madebook does hold about one.
- Roles and permissions — the role you hold comes from Bookbag; what it lets you do is decided here.