1. The portal names the signed-in account
One metadata request; no work content.
Browser → your machine
The machine prints an HTTPS address and a short code. Your browser claims that code directly from the machine; rig.rest never receives the code or the machine-issued browser token.
Model credentials are placed locally in Sovereign. If this site ever asks for one, stop: that is outside the portal's declared capability.
The order matters
One metadata request; no work content.
The pairing code and entitlement travel browser-to-machine on a different origin.
Account, machine address, paired time, and owner-chosen label—after the direct claim succeeds.