1
120-Second Single-Use Ticket Handshake
Cross-domain SSO handshakes utilize cryptographically secure UUIDv4 tickets mapped in Redis with a 120-second TTL. Tickets are burned immediately upon first exchange (
/api/v1/auth/exchange), preventing replay attacks.2
Mathematical Token-Level Authorization
User roles (
role), jurisdictional tenancy (home_country), and admin privileges are signed directly into JWT ID token Custom Claims. Downstream microservices perform sub-1ms authorization checks without hitting central databases.3
7 Standard Enterprise RBAC Roles
Access is rigorously governed across 7 explicit roles:
super_admin, founders, devops, bizops, demo_cx, customer_b2b, and customer_b2c.
