Use the current Aplauso sign-in and verification flow for the product surface you are accessing. A verified sign-in establishes the identity that the product can evaluate for its current role, tenant, assignment, and capability. It is not a self-service developer credential and does not authorize a caller to use product-owned internal routes.
Access remains scoped
Every protected product action is checked server-side against the active identity and the requested authorized scope. A copied browser header, token, employee identifier, property identifier, or visible dashboard page cannot grant cross-organization access, impersonation, administrative privileges, or a payment or payout action. Support cannot create a bypass, disclose a credential, or turn a product session into an external API key.
If sign-in or verification fails
Use the displayed recovery or verification flow and request another code only when you can receive it. Do not share the code with anyone. For help, provide the account type, the non-sensitive error, and approximate time; do not include a password, verification code, token, session value, identity document, card, or bank data.