The user center is a unified account system (UAC): all integrated projects share one global user pool, so an account registered under one project can also log in under others, with no need to build a separate account system per project.
Sessions are carried by Tokens, and each Token is bound to the project that issued it. Sign-up supports email or mobile number only and is a two-step flow: submit the credential to receive a code, and the account is created only after the code is verified, which effectively prevents bulk malicious registrations. Password recovery follows the same pattern, sending a code first and verifying before the password is changed, and a successful reset invalidates all of that user's Tokens.
Apart from the available sign-up / log-in methods endpoint and the email activation link (public GET), all endpoints require project signature authentication. Clients should query the methods endpoint first and render the form from the result rather than hard-coding the supported methods.