Skip to main content

@fairgarden/id

One account for every service in a FairGarden deployment.

People sign in with a passkey, or with a code sent to their email, and decide service by service what each one may see. The id service keeps only what is sensitive or has to be verified — an email address, a name, a phone number, mailing and residential addresses. Everything else about a person belongs to the services themselves, which can pass their own claims to each other through this one, with the person's say-so.

It is an OpenID Connect provider, built on oidc-provider⁠ (external site), so any service that speaks OIDC can sign in with it.

Start here

  • Overview — what the service does, and what each piece is for
  • Signing in — passkeys, email codes, and the sign-in in between
  • What people share — scopes, consent, and taking it back
  • Services — enrolling a service with environment variables
  • Claims from other services — how members hands its claims to events
  • Policy — decisions as Open Policy Agent policy, and their reasons
  • API — the REST API the pages use, Kubernetes style
  • Commands — pnpm db:*, pnpm keys, pnpm policy
  • Configuration — every environment variable

Run it

pnpm dev            # http://localhost:3010

Nothing else is needed locally: an embedded Postgres starts in .data/id, and email goes to the mock mailbox at /dev/mailbox.