MicrohostingsGame infrastructureBack to platform

Identity architecture01 / 03

One doorway.
Three clear boundaries.

Credential custody, application sessions, and product authorization stay deliberately separate.

  1. 01
    Credential custodyZITADEL boundary
    Provider managed
  2. 02
    Application sessionSame-origin BFF
    Active boundary
  3. 03
    Product accessTenant-aware RBAC
    Default deny
Sign in requiredThe protected route disclosed no Admin data

Secure operator access

Return to the control room.

Continue through the dedicated ZITADEL identity boundary. Microhostings receives a verified handoff and keeps product authorization in the control plane.

Protected identity handoffCredential entry stays with ZITADEL. The application receives an opaque session and resolves current permissions server-side.

Planning a new organization?Open secure signup
Credentials stay with ZITADELOpaque application session