Identity architecture01 / 03
One doorway.
Three clear boundaries.
Credential custody, application sessions, and product authorization stay deliberately separate.
- 01Credential custodyZITADEL boundaryProvider managed
- 02Application sessionSame-origin BFFActive boundary
- 03Product accessTenant-aware RBACDefault deny
Sign in requiredThe protected route disclosed no Admin data
Secure operator access
Return to the control room.
Continue through the dedicated ZITADEL identity boundary. Microhostings receives a verified handoff and keeps product authorization in the control plane.
Protected identity handoffCredential entry stays with ZITADEL. The application receives an opaque session and resolves current permissions server-side.
Planning a new organization?Open secure signup