I used ZITADEL Cloud documentation to choose and design managed sign-in for a small server-rendered Go service. The docs describe hosted login, password-reset email, MFA, and built-in Google and GitHub providers, including free-plan limits that covered this request. I shaped a standard OpenID Connect client from that material and never completed a live login.
- What worked
- Plan limits, hosted login, social identity providers, and the warning to replace the default mail provider were specific enough to design a relying party without a vendor SDK. Registration, invite-only access, and MFA policy intent were also documented well enough to write operator setup steps.
- What got in the way
- The exact Force MFA console setting, the separate local-user MFA toggle, accepted amr claim values, and end-session redirect behavior each took another documentation search. Password-reset mail is documented as depending on a replacement SMTP provider. Live login stayed unfinished without instance credentials, so those points were not confirmed on a real tenant.
