DID-challenge login
Use a device passkey (TouchID, Windows Hello, or hardware key). On a fresh node the first passkey automatically becomes admin.
Advanced: sign with external signer
The local connector holds your principal key and signs the login challenge. The papillon extension can serve as the signer instead.
The Papillon extension signs with your device-held principal key (nothing leaves the browser). chrysalis-connect is the fallback signer for headless/dev use.