
Organizations & Tenancy
Multi-tenant identity for every BlueForge app: organizations with owners, admins, and members, a personal org for every user, and invitations — all resolved from a single session.
Central authentication for the BlueForge ecosystem. Single sign-on across all your apps — plus organizations, tenancy, device-flow API keys, and org-level billing, resolved from one identity platform.

Identity, tenancy, and billing for the whole BlueForge portfolio — one platform, nothing extra to run.

Multi-tenant identity for every BlueForge app: organizations with owners, admins, and members, a personal org for every user, and invitations — all resolved from a single session.

One OAuth flow shared across the whole ecosystem. Google, GitHub, and Gitea credentials live here and federate to each app — plus an MCP OAuth resource server for mcp.app.* subdomains.

Desktop CLIs log users in once, then issue user-bound keys for unattended calls. Sibling apps resolve any key back to its owning user through the /api/v1/users/resolve verifier.

Federation Spec 1: mint scoped service accounts from the admin console, exchange them for short-lived JWTs, and resolve them on every call — no shared human credentials between services.

Stripe checkout, portal, and webhooks attach platform plans at the org level. Apps read plan and entitlements (like financials.apps.max) instead of running their own billing.

HMAC-signed organization.*, member.*, invitation.*, and key.* events fan out to every connected app, with idempotency keys and retries — so mirrors stay fresh without polling.
The real screens, from sign-in to the admin console. No mock-ups.




Start free, upgrade when you need more. No hidden fees.
For personal projects and prototypes.
For side projects and small apps going live.
For growing teams and businesses.
For large organizations with advanced needs.
Set up centralized authentication for your entire organization in minutes.