Authentication
Studio sign-in
Sign in to Gnok Studio at studio.gnok.io/login on a single page: your organization's sign-in name, your email, your password, and a second factor when your account has one (an authenticator-app or recovery code, or Use passkey). A new organization's email must be verified before its first sign-in. See account access.
Second factor
- Administrators must use a second factor. An administrator without one sets it up the first time they sign in: a passkey or an authenticator app.
- A passkey is a second factor, not a replacement for the password.
- Recovery codes are shown once when you turn on an authenticator app. Each works once in place of an app code.
- Forgot password? on the sign-in page emails a reset link that is valid for 1 hour.
For the SQL statements that manage users and an authenticator, see user lifecycle.
Authentication establishes your identity and organization; authorization determines which objects and actions you can use. See roles and privileges.
Application authentication
Connecting an application from outside Studio (JDBC, the Python SDK, Flight SQL, or the HTTP API) isn't self-service for new organizations yet. Email support@gnok.io to set up client connectivity; Gnok support provides the endpoint, client package, and supported sign-in method or credentials for your organization. Token issuers, audiences, and identity-provider integrations are managed by Gnok.
For external Iceberg engines and service integrations, catalog authentication describes OAuth client credentials and credential vending. Scope service identities to the resources they require and rotate credentials through your approved process.
Token lifecycle
Tokens expire. Use the supported refresh or sign-in flow when needed; do not store bearer tokens in shared worksheets or URLs. A new token does not grant missing table privileges. Use the relevant account controls to revoke credentials or sessions when access should end.
Security context in SQL
Gnok exposes security-context functions for supported policies and queries, including CURRENT_USER, CURRENT_ROLES, and HAS_ROLE(role). Use the SQL function reference and row-level security for policy examples.
Account administration
User lifecycle covers user state, service identities, personal access tokens, MFA, and delegated management privileges. Use only the operations authorized for your account. Platform-wide authentication configuration and emergency service access are managed by Gnok.