Consent and authentication
What members see and how existing, OAuth, and new accounts complete linking.
Consent screen
Genesis displays the partner name, proposed username/email fields, purpose of the link, and destination before showing Accept and Decline. Nothing is linked merely because the page was opened.
Declines and failed attempts are audited. Your platform should not imply that linking is mandatory unless the surrounding product genuinely requires a Genesis account.
Existing Genesis accounts
Members can sign in using their normal Genesis password or an enabled OAuth provider such as Google or Discord. OAuth accounts do not need to set a password first.
After the OAuth redirect, Genesis restores the pending link and completes it against the authenticated account. The UI shows a finishing state while the session is refreshed, preventing the new-account form from briefly appearing.
New Genesis accounts
A new member supplies an email if the partner did not provide one, selects a Genesis username, and chooses a new Genesis password or OAuth provider. If the partner supplied an email, the verified Genesis email must match it.
Email verification uses a one-hour opaque continuation so verification can finish without extending the original source token. Partner passwords are never requested or accepted.
Completion and closing
After linking, the modal confirms Account linked and navigates to the destination. A visible continue/close action remains available if automatic navigation is interrupted by the browser.
Attempting to link an external identity already attached to a different Genesis account returns a conflict and requires support review; it is never silently reassigned.