Developer Docs

Live documentation for M7 APIs, SDKs, and application integrations.

Connect to M7 Identity

Issuer: https://sso.user.m7.org

Discovery JSON: https://sso.user.m7.org/.well-known/openid-configuration

Discovery guide: https://m7.org/docs/api/sso.user.m7.org/discovery-and-keys.md

Integration quickstart: https://m7.org/docs/api/sso.user.m7.org/quickstart.md

Collections

M7 Identity provider

The provider profile is the normative public integration contract. Live discovery remains authoritative for endpoint locations and currently advertised capabilities.

Principal lists and service access

Principal lists give consumer or tenant applications a membership and policy layer that can also include machine principals. A list defines selectable roles and a default role. Each bound application separately chooses whether newly issued access tokens include an active member’s role or data; both token-enrichment switches default off. Token claims are snapshots, while UserInfo and receiver ACL introspection can return current active membership fields.

M7 can handle identity, list enrollment, policy decisions, and a shared expiring membership record for a consumer service. The receiving service still verifies sender-bound proof when required and enforces its own scopes and resource permissions. The PHP guide’s introspectAcl() API is included in the verified Token/PHP 0.1.4 ZIP.

Service capability discovery

Service capability catalogues describe exact actions and selectable bundles. This discovery is separate from OAuth and OpenID Connect endpoint discovery.

The proposed M7 standard separates Management-role defaults (role.owner, role.admin, role.member), explicit service presets (preset.*), family bundles such as post.read and post.write, and exact actions such as post.save. Bundles expand to explicit, versioned action lists. readonly grants read capabilities and allows separately selected writes.

A catalogue does not grant membership, ownership, or resource access. Receiving services must verify direct organization Management membership, owner-permitted disclosure to the receiving registration, and the organization’s actual resource permissions. The guide separates the proposed contract from current implementation gaps, including Blog’s pending organization-selection enforcement and Writer’s published-post editing limitation.

M7 Identity SDK downloads

Published development-access PHP releases and the Browser Direct/JS 0.1.0 release:

Package Version Downloads
Web/PHP 0.1.4 ZIP · SHA-256 · Manifest
Token/PHP 0.1.4 ZIP · SHA-256 · Manifest
CLI/PHP 0.1.2 ZIP · SHA-256 · Manifest
Browser Direct/JS 0.1.0 ZIP · SHA-256 · Manifest

Verify each ZIP against its SHA-256 sidecar before extraction. CLI/PHP 0.1.2 requires Token/PHP >=0.1.3 <0.2.0; use the matching Token/PHP download above.

Browser Direct/JS 0.1.0 is tagged browser-direct-v0.1.0. Its public ZIP, SHA-256 sidecar, and manifest match the SDK release files. The owner reports that all browser-direct flows worked on HenryGoss.com on 2026-09-25. See the browser-direct guide for independent login, logout, signup, account, and token-status examples and the complete integration page.

M7 C Crypto and the compiled M7 PHP Crypto extension are optional dependencies for specific cryptographic features. Ordinary base SDK installation does not require them. See optional native runtime requirements.

Get started

The SDK packages are distributed under MTL-10. Packagist installation is not currently available.