A self-hosted identity service and policy decision service, with a runnable example showing how an API can authenticate a user and enforce an access decision.
Identity establishes who is calling; policy evaluates the request; your API enforces the result.
Database-backed authentication with scrypt password hashing, rotating JWT sessions, atomic token refresh, and PostgreSQL-persisted session families with full revocation chains.
Evaluates configured security levels and compartments. It resolves source domains from trusted service credentials and role mappings instead of caller-supplied clearance.
Demonstrates session validation, a server-to-server policy request, and allow/deny enforcement before returning protected example data.
Run the services yourself and manage database access, network boundaries, policy files, key provisioning, backups, and updates as part of your deployment.
The application that owns the data remains responsible for enforcing authorization.
The API asks Identity to verify the access token and confirm the user still has an active session.
The API sends the verified subject, action, and configured target domain using a server-only credential.
The example returns protected data only after an allow decision and fails closed on upstream errors.
Capabilities describe this software, not a certification or a complete security program.
| Area | Current scope | Not provided |
|---|---|---|
| Identity | Accounts and revocable sessions | SSO, MFA, identity proofing |
| Authorization | Configured compartment decisions | Automatic enforcement in your API |
| Operations | Self-hosted example and tests | Certification, SLA, hardware isolation |
A local integration demonstrates the identity-to-policy request flow without a hosted platform.
Run the identity API against PostgreSQL
Evaluate configured domains and compartments
See the complete authorization flow locally
Common questions from compliance officers and engineering teams