- OIDC login via Authentik; first login creates a disabled user (admin approval).
- Users set/replace their Intervals.icu athlete ID + API key; the key is validated
against Intervals.icu and stored AES-256-GCM encrypted (shared key with the MCP
server). Same users table (schema owned by the MCP server's migrations).
- Admin page (gated on the intervalsicu-mcp-admins group claim): list, approve,
disable, delete users.
- 29 tests @ 93% (OIDC routes integration-only); Dockerfile asserts templates are
packaged; .gitea CI test-gates the image build.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>