Manage customer identity
Handle registration, sign-in, renewable sessions, and recovery while keeping application policy under your control.
Loading…
01 / The machinery
Back to topM7 brings Identity, Active Tags, and federation together on one shared foundation without requiring the whole stack. Use what you need. Keep what works. Add more only when it earns its place.
Three independently useful capabilities
Handle registration, sign-in, renewable sessions, and recovery while keeping application policy under your control.
Compile DOM-declared behavior into inspectable jobs and tickets without taking over rendering.
Connect capabilities across independently operated systems as the federation develops.
Modular by design
Each M7 layer is built to work on its own and connect cleanly with the others. Use one, snap several together, and keep the rest of your stack on your terms.
02 / M7 Identity
Back to topGeneral-purpose IdP / Human + machine auth
M7 Identity is a general-purpose identity provider for custom applications, organizations, and federated services. It combines OAuth 2.0 and OpenID Connect integration with multi-tenant identity, explicit human and machine principals, renewable sessions, and lifecycle control.
Identity and access lifecycle
Authenticate a person, application, service, or device and issue credentials for the intended tenant and audience.
Renew and validate session or machine authority with scoped tokens, rotation, binding, and explicit policy.
Inspect, revoke, close, recover, and offboard credentials and identities through explicit lifecycle controls.
Designed for connected systems
Manage organizations, members, groups, applications, and tenant-local policy while keeping each identity in its intended security context.
Use interactive OAuth and OpenID Connect flows for people and client credentials for service-to-service access, each governed by its own rules.
Combine discovery, PKCE, device authorization, dynamic client registration, and M7-aware session controls across custom systems.
Security focus
M7 keeps principal type, organization context, audience, scope, binding, renewal, revocation, and recovery explicit across human and machine access.
04 / Federation and adoption
Back to topM7 is designed for independent operators, not platform tenants. Use services others provide, offer capabilities of your own, and keep ownership of the products and customer relationships you create.
M7 services
Adopt one M7 service without moving the rest of your stack.
Your existing service
Federate a capability you already own and operate.
A larger product
Connect M7 services, your services, and capabilities operated by others.
A capability others need
Set access terms while retaining ownership and operation of the capability.
Keep building through what comes next
We intend to earn your business, keep it, and stand behind what we build. Exact support, maintenance, migration, and continuity commitments still need to be defined.