Signing in

Madebook has no sign-in of its own. You use the shared Bookbag account — what that means for your password, your devices, your organizations and your notifications.

Madebook does not have a login. Every Bookbag product shares one account at sso.bookbag.ai, the way every Google product shares one account at accounts.google.com.

This is not a convenience layer over a Madebook password. Madebook has no password store any more. The sign-in, registration and password-reset endpoints still exist in the server code but are not routed — they are unreachable.

What happens when you sign in

  1. You open any Madebook address, or app.madebook.ai/auth/login directly.
  2. Madebook checks whether you already have a session here. If you do, it sends you straight on to where you were going.
  3. If you do not, the page says "Taking you to Bookbag sign-in…" and hands you to Bookbag. If the redirect somehow does not fire, a Continue link on that page does the same thing by hand.
  4. You sign in at Bookbag.
  5. Bookbag hands you back, and you land on the page you originally asked for — not on a home page. The destination travels with you the whole way as a next parameter.

The handover is an OpenID Connect authorization code flow with PKCE. The in-flight verifier and state travel in a sealed, encrypted cookie that expires after 10 minutes, rather than in a database table — they are worthless sixty seconds later and belong to one browser.

The pages that no longer do anything

These addresses still exist so that old links, bookmarks and "you must sign in first" redirects keep working. Each one forwards and does nothing else.

Address Where it takes you
/auth/login Bookbag sign-in, carrying where you were going
/auth/register sso.bookbag.ai/auth/register
/auth/resetpassword sso.bookbag.ai/auth/resetpassword
/auth/changepassword sso.bookbag.ai/auth/resetpassword
/account/profile sso.bookbag.ai/user/profile
/account/sessions sso.bookbag.ai/user/profile
/organizations/<id>/people The organization's page at Bookbag account, sso.bookbag.ai/user/organizations/<id>
/organizations/<id>/chat The same organization page
/organizations/<id>/storage The same organization page
/organizations/<id>/ai The same organization page

The four organization addresses were Madebook's People, Chat, Storage and AI self hosted pages. Those pages are gone: people, chat, files, storage and AI settings are managed on the organization's page at Bookbag account, for every product at once.

If you are looking for your name, your password, or your signed-in devices, they are all in one place: your Bookbag account.

How long a session lasts

Your Madebook session is one row per signed-in device. Three numbers govern it:

Idle timeout 12 hours
Absolute maximum age 30 days
Sliding renewal If more than 15 minutes have passed since the session was last seen, the 12-hour window restarts.

Expiry is enforced on the server on every request. An expired row — or one past the 30-day absolute limit — is deleted on sight.

A session is also refused, identically, when the Bookbag account is paused or blocked, when the local profile is missing, or when the profile is deactivated. All of those look the same from the browser: you are sent to sign in.

When a request arrives with an expired session, the API answers HTTP 200 with a redirect envelope rather than a 401, and the web app turns that into a sign-in redirect that preserves where you were. The message is "Your session has expired." Two other connection failures you may see instead:

  • "Could not reach the Madebook API. Is it running?"
  • "The API returned something that was not JSON."

Signing out

Signing out of Madebook ends the shared session at Bookbag as well, and lands you on the Bookbag sign-in page.

That is deliberate. A local sign-out on its own would bounce you through /auth/login, find the Bookbag session still alive, and sign you straight back in — which looks exactly like a sign-out button that does not work.

The reverse also holds. Ending a device's session from your Bookbag account ends its Madebook session with it: the SSO session id recorded when you signed in is checked on every request.

What lives at Bookbag and not in Madebook

This is the part worth understanding before you go looking for a settings page that is not there.

Thing Where
Your name and profile Bookbag
Your password Bookbag
Your signed-in devices Bookbag
Organizations — created, named and peopled Bookbag
Who is in an organization, and their role Bookbag
An organization's chat, files, storage and AI settings Bookbag
Your notification inbox Bookbag, read through Madebook
Everything else — workspaces, repositories, missions, sessions, governance Madebook

Your name and picture are the account's too, and Madebook keeps no copy of them. Its own user record holds the account id and nothing else about you (plus what is Madebook's own: a job title, a timezone, the platform-admin flag). Every page that shows people asks Bookbag who those account ids are, once per request — so a name changed at Bookbag is the name on the next page load in every product, with nothing to sync and nothing that can go stale.

Madebook never stores an organization or its members. It asks Bookbag, on the server, authenticated with its app token (SSO_APP_TOKEN), and keeps the answer for a few seconds so that a page checking your role five times makes one call. Every write clears that cache for the person who made it.

That is also why there is no People row in the sidebar. Who is in the organization is the account's answer, not Madebook's, so every door to it — Manage organization ↗ on the organization's Home, Manage ↗ on Overview — opens Bookbag account in a new tab rather than a second copy here.

If Bookbag is unreachable

Reads against Bookbag never throw. A failure answers the question conservatively — no organizations, no role — so an outage narrows your access rather than widening it. You will see fewer organizations than you have, not more, and no page will grant you a permission you do not hold.

There is a 6 second timeout on each call and a 15 second cache on the answer.

Your notifications

The bell in the header reads the Bookbag inbox through Madebook's server. Marking one read, or removing one, happens at Bookbag. The "see all" link at the bottom of the panel goes to sso.bookbag.ai/user/notifications.

Alongside the shared inbox, the bell also shows Madebook's own attention items for the workspace or organization you are in, linking to that scope's Attention page.

  • Organizations — the tenant, and what Madebook does hold about one.
  • Roles and permissions — the role you hold comes from Bookbag; what it lets you do is decided here.