Strong by default
Passwords never stand alone.
Require a verified passkey or security key before a management session becomes trusted.
One focused control plane for passkeys, Projects, OAuth, service credentials, and the evidence behind every decision.
Project boundary
Assurance
Strong
Token TTL
10 min
Signing
RS256
Authentication activity
Last seven days
Passkey challenge verified
User verification · 18 ms
One boundary for
The platform
ComplicatedAuth turns identity infrastructure into explicit, inspectable boundaries—so your team can reason about who is trusted, for what, and for how long.
Strong by default
Require a verified passkey or security key before a management session becomes trusted.
Project isolation
Keep users, origins, service accounts, policies, and activity scoped to the Project that owns them.
OAuth + OIDC
Short-lived RS256 tokens, rotating signing keys, online revocation, consent, and exact audience checks.
Operational truth
PostgreSQL-backed throttling, idempotency, audit trails, and leased background work across replicas.
A cleaner trust path
Your BFF holds Project credentials and exchanges browser-safe references. The browser sees only what it needs; ComplicatedAuth enforces the rest.
Explore the architectureBrowser
Opaque references
Your BFF
Credentials stay here
ComplicatedAuth
Policy + assurance
Security is a system property
Recovery revokes active sessions. Credential removal is auditable. Migrations are checksummed. Rate limits fail closed when their state is unavailable.
Create a Tenant, define your first Project, and put strong assurance between your users and production.