Operator console
Operators are provisioned by a security administrator. Sessions end after 15 minutes idle and 8 hours at most.
A one-time code is sent to provisioned operator addresses only. In the sandbox it lands in the local mail spool (pnpm auth:code).
pnpm auth:code
Sandbox: e-mail one-time code only. A second factor is a recorded follow-up before any hosted deployment.