Sign in
Credentials and OAuth tokens stay on the server as HttpOnly cookies — nothing sensitive is returned to browser code.