Product
Everything behind your sign-in.
An OpenID Connect issuer for each of your brands, the apps and APIs that trust it, and the API your team runs it all with. Each part below says whether it is built, meaning in Synq’s code and tested today, or still being built for the first release.
Issuers
One issuer per brand.
An org is your company. Each brand inside it is one user pool and one OpenID Connect issuer, at https://<your-slug>.auth.synq.build, with its own discovery document and keys.
Orgs and brands
Run several products under one org, each with its own users, apps and settings. An issuer URL never changes once apps trust it.
Signing keys that rotate
Keys are encrypted at rest and rotate on a schedule: a new key is published a day before it signs, so apps that cache keys never break.
Standard endpoints
Discovery, JWKS, authorization with PKCE, token, userinfo, introspection, revocation and sign-out, built on oidc-provider, a widely used open-source OpenID Connect library.
Apps and APIs
Every app your team ships.
Register each app with its type and exact redirect URIs. Register each of your APIs with its scopes, and decide which apps may ask for which.
Web, single-page and native apps
The authorization code flow with PKCE, exact redirect URIs and refresh tokens that rotate. Confidential apps get secrets that are shown once and stored hashed.
Machine-to-machine
Services get tokens with their own credentials, only for the APIs and scopes you granted them.
CLIs and AI agents
The device flow signs a person in to a CLI or an agent, and every token and audit record says which agent acted for whom.
MCP hosts
MCP clients can sign your users in without being registered first, through client ID metadata documents or dynamic registration, with consent.
Your APIs and scopes
Access tokens are JWTs meant for one API, living 5 to 15 minutes. An app asking for a scope it may not have is refused, never silently trimmed.
Sign-in
Sign-in your users recognise.
Users sign in on a page served by their brand’s issuer. Each method is a step in one pipeline, so a new method never touches the protocol.
Email and password
Passwords are hashed with Argon2id and, unless a brand turns the check off, checked against known breaches, with only five characters of a hash ever leaving Synq. Repeated wrong guesses are slowed down, then locked out.
Wallets, social accounts and passkeys
Solana wallets with signed messages (never a transaction), Google, Microsoft, Discord, Apple, X, Facebook, Telegram, Matrica and passkeys.
Your brand on every page
Hosted pages themed per brand, and your own OAuth credentials so providers’ consent screens show your company’s name.
Operations
Run it from your own systems.
The management API is how you run Synq today, and it is what the dashboard will be built on. Your team, your keys and your users stay in your hands.
Management API and API keys
A documented /v1 API with an OpenAPI contract that never breaks within a version. Keys carry only the permissions you give them, and can be limited to your IP addresses.
Users
Search a brand’s users, update their profile and metadata, end their sessions, disable them, or delete them after a 30-day grace period.
Team members and roles
Invite teammates by email, give them built-in or custom roles, and never let anyone grant more than they can do themselves.
Audit log and webhooks
Every change is recorded with who made it and from where. Webhooks follow the Standard Webhooks signature scheme and retry with backoff.
Dashboard and SDKs
A self-serve dashboard, and @synqauth SDKs for JavaScript, Next.js, React, React Native and Solana. Any OpenID Connect library works in the meantime.
Sign-in methods
Every method, one by one.
- Email and passwordBuilt
- Email codes and magic linksBuilding
- PasskeysBuilding
- Solana walletsBuilding
- GoogleBuilding
- MicrosoftBuilding
- DiscordBuilding
- AppleBuilding
- XBuilding
- FacebookBuilding
- TelegramBuilding
- MatricaBuilding
Want it before it is finished?
Tell us what you are building and which parts matter most to you.