Sign-in & your data

A familiar way
to say hello.

Tether uses your GitHub, Microsoft or Google account to know who you are. This page explains what happens when you sign in, what Tether asks for and what it keeps.

What happens when you sign in

  1. In VS Code, open the Tether view and select Sign In, then choose a provider.
  2. Your browser opens the provider's own sign-in page. You enter your password there, never in Tether.
  3. The provider sends you back to Tether's server at api.teth3r.app, which returns you to VS Code.
  4. The first time, you choose a Tether username. Teammates use it to invite you.

What Tether asks your provider for

Only enough to identify you. Tether does not ask for your repositories, mail, files or calendar.

Permissions requested from each sign-in provider
ProviderPermissions requestedWhat they allow
GitHubread:user, user:emailRead your public profile and your email addresses.
Microsoftopenid, profile, emailConfirm your identity and read your name and email.
Googleopenid, email, profileConfirm your identity and read your name, email and profile picture.

Tether uses the provider's token only during sign-in, to read who you are. It does not save the provider's tokens and does not use them afterwards. It does not request offline access to your account.

What Tether stores

  • The account ID your provider gives Tether, so you're recognised next time.
  • Your email address and, for GitHub, your username. These help match invitations to you.
  • Your display name, a link to your profile picture if your provider shares one, and the Tether username you choose.
  • Your projects' files, comments and memberships, so your team can work on them.

How you stay signed in

After sign-in, Tether gives VS Code its own session: a short-lived access token that lasts 15 minutes, and a refresh token that renews it. Each refresh token can be used once and is replaced every time it is used. If it isn't used for 30 days, you'll need to sign in again.

The extension keeps these tokens in VS Code's secret storage, which uses your operating system's keychain where one is available. Signing out ends the session on Tether's server as well as in VS Code.

Please keep in mind

Tether is a student project (DECO3801 at The University of Queensland). It has not been independently security audited and is not endorsed by the university. Avoid sharing projects that contain secrets, such as passwords, API keys or private data.

Questions? Ask us.