Identity service ready

Identity and access policy
for internal APIs

A self-hosted identity service and policy decision service, with a runnable example showing how an API can authenticate a user and enforce an access decision.

Identity validates the active session, Policy decides allow or deny, and your API enforces the decision.
PostgreSQL Identity storage
15 minutes Access token lifetime
Deny by default Policy decisions
Runnable Internal API example
✓ Self-hosted services
✓ PostgreSQL-backed sessions
✓ Configured policy evaluation
✓ Example API enforcement

A small, composable access stack

Identity establishes who is calling; policy evaluates the request; your API enforces the result.

Identity service

Database-backed authentication with scrypt password hashing, rotating JWT sessions, atomic token refresh, and PostgreSQL-persisted session families with full revocation chains.

Policy decision service

Evaluates configured security levels and compartments. It resolves source domains from trusted service credentials and role mappings instead of caller-supplied clearance.

Example API integration

Demonstrates session validation, a server-to-server policy request, and allow/deny enforcement before returning protected example data.

Operator-controlled deployment

Run the services yourself and manage database access, network boundaries, policy files, key provisioning, backups, and updates as part of your deployment.

Request flow

The application that owns the data remains responsible for enforcing authorization.

1

1. Identity validates the session

The API asks Identity to verify the access token and confirm the user still has an active session.

2

2. Policy evaluates the request

The API sends the verified subject, action, and configured target domain using a server-only credential.

3

3. The API enforces the decision

The example returns protected data only after an allow decision and fails closed on upstream errors.

Scope and limitations

Capabilities describe this software, not a certification or a complete security program.

AreaCurrent scopeNot provided
IdentityAccounts and revocable sessionsSSO, MFA, identity proofing
AuthorizationConfigured compartment decisionsAutomatic enforcement in your API
OperationsSelf-hosted example and testsCertification, SLA, hardware isolation

Start with the example

A local integration demonstrates the identity-to-policy request flow without a hosted platform.

Identity
Self-hosted

Run the identity API against PostgreSQL

  • Registration and login
  • Short-lived access tokens
  • Rotating refresh sessions
Start Building
Example API
Runnable

See the complete authorization flow locally

  • Validates active identity sessions
  • Calls Policy with a private credential
  • Fails closed on upstream errors
Request Briefing

Institutional FAQ

Common questions from compliance officers and engineering teams

Does Aarchon provide financial trading or compliance infrastructure?
No. Aarchon is an identity and configured policy-evaluation toolkit for internal APIs. It does not provide trading execution, certification, or a compliance program.
What compliance frameworks are supported?
No. The project has not been certified or independently assessed against those frameworks. Operators must evaluate the complete deployment and organizational controls for their own requirements.
How does an API enforce a policy decision?
The example asks Identity to validate the current session, then requests a policy decision. It returns sample data only on an allow decision and fails closed when an upstream service is unavailable.
What is the data isolation model?
The policy service can deny requests across configured compartments. The application must enforce that decision, and the deployment must protect service credentials, networks, and stored data.