Governance · Authoring access
Sign in
Authoring surfaces use Google sign-in with an explicit allowlist. Public documentation and distribution endpoints stay readable without a session.
Design Manager authoring
Sign in to access Publish, Design lab, and the publish API. The session cookie is host-only and scoped to this design-system app.
01
Access boundary
Only authoring routes are gated. Public registry reads and documentation stay open.
Gated paths: /publish, /api/publish, and /design-labs. Public feeds such as /api/tokens.css, /api/tokens.json, and /api/registry.json remain open for consumers.