@fairgarden/id
One account for every service in a FairGarden deployment.
People sign in with a passkey, or with a code sent to their email, and decide service by service what each one may see. The id service keeps only what is sensitive or has to be verified — an email address, a name, a phone number, mailing and residential addresses. Everything else about a person belongs to the services themselves, which can pass their own claims to each other through this one, with the person's say-so.
It is an OpenID Connect provider, built on oidc-provider (external site), so any service that speaks OIDC can sign in with it.
Start here
- Overview — what the service does, and what each piece is for
- Signing in — passkeys, email codes, and the sign-in in between
- What people share — scopes, consent, and taking it back
- Services — enrolling a service with environment variables
- Claims from other services — how members hands its claims to events
- Policy — decisions as Open Policy Agent policy, and their reasons
- API — the REST API the pages use, Kubernetes style
- Commands —
pnpm db:*,pnpm keys,pnpm policy - Configuration — every environment variable
Run it
pnpm dev # http://localhost:3010
Nothing else is needed locally: an embedded Postgres starts in .data/id,
and email goes to the mock mailbox at /dev/mailbox.