Sylphx Identity

Docs · explanation

One writer. Closed when unproved.

A consuming product integrates Identity once and receives a coherent trust path for people and workloads. Missing, stale, or revoked project scope, identity, or authority fails closed.

Two public hosts, two jobs

Product site
https://identity.sylphx.com — this documentation, Product Contract, first success, and pricing/trust. Identity authors the content. Platform owns DNS/HTTPRoute desired spec; Hands applies kube. This page does not implement those.
API peel
https://api.identity.sylphx.com with public contract /v1 and /.well-known/jwks.json. Marketing HTML on the peel is a defect. The JSON door is not this site.
Discovery
Callers take api_base from the current Platform Project Binding. Do not compile sibling product hostnames.

What you can do

  • Create and resolve customer and workload principals inside the signed project scope.
  • Authenticate people into opaque Identity sessions (password, OIDC, passkey, MFA). Authenticate workloads as workloads. Neither session is a delegation.
  • Mint a short-lived Plan-bound delegation that is a strict subset of the current Platform Binding ceiling. Lifetime is at most 300 seconds.
  • Revoke binding head, principal, credential, session, grant, or delegation and have that authority close at use.
  • Record purpose-specific consent and project-scoped privacy requests without Identity owning the consuming product's customer data.

Authority that is not this product

  • Platform owns project/environment composition, Binding mint, deployment, and peel/site DNS/HTTPRoute desired spec.
  • Identity verifies Binding and stores the verified project_id as external scope. It does not mint Binding.
  • Events owns delivery transport for Identity delivery intents (email verification, recovery).
  • Hands materializes Kubernetes objects.
  • Consuming products own customer-facing login and admin screens. This site is not that console.

Residual, not destination

Sigil and Keynesta remain residual dead. sigil.sylphx.com, kn_secret, and leftover Console dens are not dest. {name}.api.sylphx.com is never a product API. console.sylphx.com is not this site. HTTP 404 on leftover DNS is not writer-count 0. A site/ tree is not live completeness.

This documentation is dest speech and source content. It is not proof that live is empty or that live is complete.