Basics: what CIAS is and what it is not
The terms and the split you need to understand any CIAS flow: the objects and their owners, tenant and group, the two permission matrices, the write direction, and the ceiling.
CIAS as a bridge to the identity providerThe objects and who owns themTenant, organization, groupThe two permission matricesThe ceiling: nobody grants more than they have
Login and token
How a person or a service gets a token, how it is renewed and ended, and what happens with the token on every request.
Sign in in the browserSign in as a service (client credentials)Session in the BFF and cookiesRenew the tokenSign outWhat happens with the token on every requestToken exchangeWhat is read from the tokenEffective roles: global or in the tenantWhy revoking permissions takes effect with a delay
Registration
How a person becomes a user: one flow with four variants, email verification, password at Keycloak, approval, tenant assignment, initial roles, hooks and emails.
One flow, four variantsThe states of a registrationSelf-registrationCreation by the platform administratorInvitation by the tenant administratorRedeem an invitationThe email is the accountVerify the emailSet the passwordApproval by an administratorWhere the tenant comes fromWhat happens on completionInitial roles as a rule setYour own logic: hooks and eventsProtecting the public endpointsClean up abandoned registrations
User management
The user record in CIAS from the subject area view: status, suspend, close, move, maintain attributes, and why the order of the write operations decides security.
The user recordThe lifecycle of a userThe write orderSuspend, reactivate, closeImport existing accountsRename and change the home tenantMaintain a person's attributesResend the password setup linkSelf-service: own tenant and language
Tenants
The tenant as the isolation boundary: static or dynamic, its business status, its technical rollout, how it is resolved and admitted on every request, and how you switch between tenants.
Static and dynamic tenantsThe lifecycle of a tenantCreate and provision a tenantThe tenant keySuspend and close tenants, validityDetermine the tenant of a requestAdmit the tenant (tenant gate)Switch between tenantsIn SINGLE the tenant in the token does not countWorking for a tenant without a request
Grant roles and permissions
The role catalog, the levels of a role, how modules register their roles, who may grant roles, time-limited grants, and how a role gets into the token.
The role catalogRealm role, client role, organization roleModules register their rolesReconciliation with KeycloakHow a role gets from the code into the tokenGrant a roleTime-limited rolesRevoke a roleThe platform's realm roles
Connection to the identity provider
How CIAS talks to Keycloak without the business modules knowing Keycloak: ports and adapters, the Keycloak adapter, the in-memory adapter for tests, and the Keycloak extension.
Ports and adaptersThe Keycloak adapterThe in-memory adapter for tests and developmentThe Keycloak extension for the password link
Security principles
The principles behind every CIAS process, in one place: refuse when in doubt, indistinguishable refusals, no defaults for permissions, and behavior during outages.
Reject when in doubtRejections that reveal nothingWhen CIAS or Keycloak fails