OSCR

Signing in and your account

Reading needs no account. Signing in is for contributing: submitting a paper, claiming it, correcting its links, validating its map, adding the badge, asking for a removal. You sign in with an identity you already have, and OSCR never asks for your email address.

Why sign in

A contribution changes a public record, so the registry needs to know who asks and in which role — an author of the paper, a maintainer of its code, anyone else — and to answer them. It does that with the identity providers researchers already use, not with a password of its own.

ORCID, GitHub or Google

ORCID
The best choice for an author: when a paper's metadata lists your ORCID iD, you are recognized as its author at once. OSCR asks ORCID for the openid scope only — your iD and your public name.
GitHub
The way to be recognized as a maintainer of a repository on GitHub. OSCR asks GitHub for no scope at all: public information only, of which it reads your account's number, login and name — never an address, even a public one.
Google
For anyone else. OSCR asks Google for the openid scope only: an opaque identifier, not even a name.

Each sign-in goes to the provider's own page and comes back to the page you were on. It is protected against forged or replayed returns (a short signed cookie holds the flow's secrets for ten minutes). While the platform is being built, sign-in with ORCID may use ORCID's sandbox — a test service — and then says so; anything validated through it is recorded as a test.

What signing in keeps, and never

  • Kept: the name the provider gives (ORCID's public name, GitHub's name or login; Google gives none), your public handles (ORCID iD, GitHub login), each provider's identifier for you, your roles, your requests and their answers, and for each session a short description of the browser ("Firefox on macOS").
  • Never: an email address; a password; the provider's access token, used during the sign-in only and then dropped; your session's identifier itself — the database keeps only its SHA-256.

The privacy page lists every column of every table.

Signed in, choose another provider on your account page: its identity joins your account, so that, for instance, an author who signed in with ORCID can also prove maintainership on GitHub. One identity per provider; an identity already linked to another account is refused.

Roles: verified author, maintainer

Member
Everyone signed in: may submit a paper, claim authorship, and ask for a removal.
Verified author
Of a given paper: automatically, when your account's ORCID iD is among the paper's authors in its published metadata — checked at each sign-in, and again with "Check my papers again" on your account page. Otherwise, by a claim, verified by the registry's rules when Crossref's automatic update has put the paper in your ORCID record, or accepted by the operator. A verified author may correct the paper's links, validate its map, and have their removal requests applied at once.
Maintainer
Of a given repository: on GitHub, checked at once with your GitHub identity — you own it, are a public member of the organization that owns it, are among its contributors, or authored a commit in it. Otherwise, and elsewhere (GitLab, Codeberg…), your claim waits for the operator, 30 days at most, then is closed with how to be checked again. Only a maintainer who owns the repository or is a public member of its organization (or one the operator made) may correct the links of the papers whose code it is, for that repository, and have a removal of its copies applied at once: a contributor or a commit's author may not (why).

Your account page

Your account page shows who you are signed in as, your linked identities, your roles, the papers that list your ORCID iD, the form to claim a repository, and every request you made — submissions, corrections, validations, claims, removal requests — with its status and the answer.

Notifications

Notifications stay in the site, by decision: OSCR sends no email. Today, the answers to your requests appear on your account page and on the pages concerned (a removal request's page shows its decision and its words). Notifications of their own — new activity on your papers — will come later, still in the site only.

Sessions and signing out

A session lasts 30 days from your last visit (renewed at most once a day), in a cookie your browser sends to this site only and that page scripts cannot read. A second, harmless cookie tells the pages that you are signed in, so that a signed-out reader's visit never asks the site anything. "Sign out" on your account page ends the session and deletes it. The privacy page lists the cookies.

What is not possible yet

  • Unlinking an identity from the site itself; signing out of every browser at once. Deleting your account is possible: ask for it on your data and your rights, and it is deleted within about ten minutes, with its sessions, identities, roles, claims and requests.
  • Maintainer checks outside GitHub cannot be made automatically: such a claim waits for the operator, 30 days at most, then is closed. Archives (Zenodo, OSF) have no owner in their address, so no maintainer claim.