Phase 1 uses the admin API token to sign in. It is stored in a server-side session cookie and is never exposed to the browser.