01
Identity
Choose the public GitHub identity connected to your account, or provide your canonical public X profile page. GitHub is linked through sign-in. X is explicitly marked as publisher-provided because no X API verification is performed.
02
Two token boundary
- The build token can validate a manifest and upload a private draft, but cannot publish.
- The website shows every public field and preview before confirmation.
- Only confirmation creates a short-lived one-time publish token.
- The publish token is bound to the session, draft fingerprint, creator identity, and expected archive.
03
Agent handoff
Paste the Session Prompt into Codex. The CLI performs the validation and waits while you review the exact listing in the browser. It can continue only after the website issues the publish token.