Documentation Security Updated

Signing in

How PluggedDesk signs in to PluggedHub through Exprezoe Identity, what it keeps afterwards, and how to sign out.

Who this is for

Signing in connects PluggedDesk to PluggedHub, with your Exprezoe Identity account. Today that is for people at Exprezoe. You do not need to sign in to use PluggedDesk for Remote Desktop connections of your own.

Signing in

  1. Choose the account button at the bottom of the activity bar, then Sign in with Exprezoe Identity.
  2. Your browser opens at Exprezoe Identity. Sign in there as you always do, with your second factor.
  3. The browser says that you can close the tab, and PluggedDesk shows your name.

PluggedDesk never sees your password and never asks for it. There is no place in PluggedDesk to type one. If a window that looks like PluggedDesk asks for your Exprezoe password, it is not PluggedDesk.

What happens, step by step

Step What it means
PluggedDesk asks PluggedHub where to sign in The hub names the identity provider. PluggedDesk goes only to an address over HTTPS.
PluggedDesk listens on your own computer On 127.0.0.1, on a port chosen for this one sign-in. Nothing outside your computer can reach it. It stops listening when the sign-in ends, and after five minutes in any case.
Your browser opens With a one-time proof (PKCE) that only this PluggedDesk can complete. A sign-in that was started elsewhere cannot be finished here, and the other way round.
You sign in At Exprezoe Identity, in your browser.
The answer comes back to your computer PluggedDesk checks that it belongs to the sign-in it started, then checks the signature of what Identity sent, who issued it, who it is for, and that it is fresh.
PluggedDesk shows it to PluggedHub The hub checks it again, by itself, and answers with a session for PluggedDesk.

What PluggedDesk keeps

A session token for PluggedHub, in Windows Credential Manager. It is not your password and cannot be turned into it. It can be revoked, on the hub, at any time, and it ends by itself.

PluggedDesk does not keep what Identity sent. It is used once and dropped.

Signing out

Choose the account button, then Sign out. PluggedDesk tells the hub to end the session, and removes the token from the vault, whether or not the hub could be reached.

Signing out of PluggedDesk does not sign you out of Exprezoe Identity in your browser.

When it does not work

PluggedDesk says It means
PluggedHub is not set up for signing in from PluggedDesk yet The hub answered, and has the feature switched off. Nothing is wrong with your account or your network.
The sign-in was not completed The browser tab was closed, or five minutes passed. Start again.
Sign in with a second factor Identity signed you in without one. Use your authenticator or your security key.
Your account is not in a group that may use PluggedHub Ask an administrator.
Your session has ended The token was revoked or has run out. Sign in again.

An installation without a license

People at Exprezoe can use the same sign-in in place of a license key: Help › License › Sign in with Exprezoe Identity. See Licenses and seats.