Identity that is already serious
Password auth, generic social OIDC, and opaque browser sessions are wired into one clear flow.
Multi-tenant SaaS foundation
Built for identity from day one.
A quiet, production-minded starting point for SaaS products that need secure users, clean tenant boundaries, and agent access.
MIT licensed · self-hosted · your cloud
Built on boring, durable primitives
The foundation
Keep the reliable parts predictable so your team can spend its attention on what customers actually buy.
Password auth, generic social OIDC, and opaque browser sessions are wired into one clear flow.
Workspaces, projects, roles, and scoped API keys keep every customer and environment in the right lane.
OAuth 2.1, OIDC, protected-resource discovery, consent, and Streamable HTTP MCP ship together.
A short path to useful
Your users sign in, choose their context, and authorize tools without leaking product-specific decisions across the stack.
Give each customer a clean tenant boundary and a default project.
Use the Rust API from the web app, a service, or your own client.
Grant one project and only the scopes that the agent needs.
Security is the product
Credentials are treated like credentials. Tenant context is explicit. Agent grants are narrow and inspectable.
Read the security modelQuestions, answered
A Next.js app and landing page, an Axum and Tokio API, PostgreSQL persistence, OAuth/OIDC, scoped API keys, and a protected MCP endpoint.
Yes. The starter keeps the OIDC boundary generic so your provider and deployment choices stay yours.
No. The application and infrastructure stay separate, so you can point the same product at the cloud setup you already operate.
Start with the foundation
Identity, tenancy, and agent access are ready when you are.