Password Login
The default. A one-time setup token from the API log plus a password you choose. Works from any browser that can reach your instance.
OIDC / Identity Provider
Sign in with Google, Keycloak, Authentik, or any OpenID Connect provider. Required for passwordless Claude web and ChatGPT OAuth connections.
Personal Access Tokens
For scripts, the REST API, and MCP clients like Claude Desktop and Claude Code. Your browser session is never used by these clients.
Which method is used where
You cannot be locked out of plamotrack without a recovery path. See the relevant page for recovery options specific to your auth mode.