Governance · Authoring access

Sign in

Authoring surfaces use Google sign-in with an explicit allowlist. Public documentation and distribution endpoints stay readable without a session.

Design Manager authoring

Sign in to access Publish, Design lab, and the publish API. The session cookie is host-only and scoped to this design-system app.

01

Access boundary

Only authoring routes are gated. Public registry reads and documentation stay open.

Gated paths: /publish, /api/publish, and /design-labs. Public feeds such as /api/tokens.css, /api/tokens.json, and /api/registry.json remain open for consumers.