〈AUTHENTICATION TIERS〉
〈FOUR MODES〉
/PROTOCOL:HTTPS
CLOUD PROVIDER LOCAL-FIRST ENTERPRISE
NATIVE OPEN CROSS-PLATFORM
LAND:
↳EDITOR WITHOUT CHROMIUM
- TARGET:
- MACOS / WINDOWS / LINUX
- LICENSE:
- CC0
- SIGNAL:
- LOCAL-FIRST

〈CLOUD PLAN〉
/PROTOCOL: HTTPS / TLS 1.3
- STATUS:
- PLANNED
- BADGE:
- Online
FEATURES:
- Sync Planned workspace sync across devices
- Backup Planned encrypted backup for selected configuration
- Team Planned shared team workspace support
- Extensions Marketplace installation is planned after local extension paths stabilize
- Remote Remote development integration is planned
CAPABILITIES:
Planned account tokens for hosted services Okta SSO belongs to the enterprise plan MFA support depends on the configured identity provider Gateway RBAC is planned Audit logging is planned Developer certificate automation is planned
〈PROVIDER PLAN〉
/PROTOCOL: OAuth 2.0 / PKCE
- STATUS:
- PLANNED
- BADGE:
- OAuth 2.0
FEATURES:
- GitHub GitHub identity is planned as a low-friction sign-in option
- SSO Single sign-on across Land services is planned
- Repository Settings sync tied to provider identity is planned
- Team Organization and team membership sync is planned
- CI/CD CI/CD integration belongs to later portal work
CAPABILITIES:
OAuth 2.0 / PKCE support where provider flows are enabled Minimal OAuth scopes - only what each provider integration requires Refresh token handling depends on provider configuration Webhook subscriptions are planned Organization-level access policies are planned Developer certificate automation is planned
〈LOCAL-FIRST〉
/PROTOCOL: mTLS / WebSocket planned
- STATUS:
- PLANNED
- BADGE:
- Local-First
FEATURES:
- Air Daemon Browser-to-daemon loopback control is planned
- Build Launching builds from the website console is planned
- Deploy Deploying changes into a running editor is planned
- Configure Editor configuration management is planned
- Extensions Installed VS Code extensions run unmodified through the Cocoon path when their APIs are implemented
- Offline Local editor operation should not require a cloud login
- Embedded SaaS Embedding portal surfaces into the editor is planned
CAPABILITIES:
Short-lived local credentials are planned mTLS mutual authentication is planned for daemon control CRDT state synchronization - planned for conflict-free offline edits Fully local team management is planned Local certificate authority code exists in Mountain; portal integration is planned WebSocket loopback connection is planned Local RBAC policies are planned Encrypted local backup is planned
〈ENTERPRISE PLAN〉
/PROTOCOL: OIDC / SAML 2.0 / SCIM planned
- STATUS:
- PLANNED
- BADGE:
- Planned
FEATURES:
- Okta Okta SSO integration is planned
- Azure AD Azure AD / Entra ID integration is planned
- SAML 2.0 SAML 2.0 support is planned
- SCIM SCIM provisioning is planned
- Groups IdP group to Land role mapping is planned
- Audit Audit export is planned
CAPABILITIES:
OIDC discovery is planned Just-in-time provisioning is planned MFA enforcement depends on the configured IdP Session duration policy is planned Organization CA certificate management is planned Compliance documentation is planned