Problem
The problem
Every application needs a way to log in, and every application that writes its own gets it slightly wrong.
Build
What we built
One sign-in system on its own machine, handling the login for everything else we run. The apps never see a password: the sign-in tokens stay on the server, and the browser holds only a session cookie that scripts on the page cannot read.
Result
Where it got to
Live, hardened against an eighteen-point checklist, and shared by the portal, the dashboard and the operations console. Adding sign-in to a new app is now mostly configuration, which is why we can offer it as standard rather than as a line item.
Stack
Technology
- Keycloak
- OpenID Connect
- OAuth 2.0
- PKCE
- nginx
- PostgreSQL
- DigitalOcean
Want the same standard applied to your problem?
Bring the problem to a free 45-minute consultation. Nothing to prepare.