Signing in with an email address
Google was the only way in. There is now a dialogue with sign-in, sign-up, a password reset and a one-time code, and an unconfirmed account is held back: no publishing by link, and ten documents rather than five hundred, until the address is confirmed.
Handing a third party a new relationship in order to keep a text file is a lot to ask, and for the first weeks it was the only thing on offer. There is now a form beside the Google button. If the address is the same one, it is the same account.
It is a dialogue, not a page
Signing in, signing up, asking for a reset link and entering the confirmation code are four views of one dialogue, over whatever you were already doing. Somebody here is usually in the middle of converting something, and a navigation loses the document they had open; changing your mind between "sign in" and "sign up" costs nothing for the same reason. Google sits below the form rather than above it — the form is what the dialogue is for now, and the button that leaves the page belongs after the one that does not.
No password rules are listed anywhere in it. The identity service enforces its own minimum, this application does not know what that minimum is, and a list of requirements that disagrees with the server is worse than no list at all: it tells you a password is fine and then refuses it. You get whatever the service actually said instead.
Where the session comes from
Identity is Neon Auth's rather than ours, Google included — that is its provider, not a second integration here. The service lives on its own hostname, so letting the page talk to it directly would make its session cookie a third-party cookie for this site, and browsers are steadily refusing to carry those. Everything under /api/auth/ is forwarded through this origin instead, and the cookie coming back has its Domain attribute stripped off. It then belongs to this site, first-party, and is carried without argument.
Until the address is confirmed
An unconfirmed account keeps ten documents rather than five hundred, and cannot publish a document to a link anybody can open. Sharing with named addresses works either way, because that names people and asks each of them to sign in — it puts no page on the open web.
Neither limit is a trial or a paywall. An address nobody has proved cannot be recovered, cannot be told anything, and costs nothing to make a hundred of, so the two things held back are the two that matter: accumulating storage, and putting a page on the public internet under our domain. Entering the code lifts both on your very next request rather than your next sign-in. An account that arrived through Google is confirmed already — the provider asserts the address, so there was never anything here to confirm.
Related: sharing a document as a link, and turning an assistant's output into a page.