Developer Docs
Live documentation for M7 APIs, SDKs, and application integrations.
Connect to M7 Identity
Issuer: https://sso.user.m7.org
Discovery JSON: https://sso.user.m7.org/.well-known/openid-configuration
Discovery guide: https://m7.org/docs/api/sso.user.m7.org/discovery-and-keys.md
Integration quickstart: https://m7.org/docs/api/sso.user.m7.org/quickstart.md
Collections
- API documentation
- SDK documentation
- M7 Identity SDK
- Principal lists and inbound machine access
- Service capability discovery and organization-member permissions
- Browser-direct JavaScript SDK and examples
- Plain-text documentation index for AI tools
M7 Identity provider
- OAuth 2.0 and OpenID Connect provider profile
- Provider capability card
- Integration quickstart
- Discovery and signing keys
- OpenID Connect discovery JSON
- OAuth authorization server metadata
- Public signing keys (JWKS)
The provider profile is the normative public integration contract. Live discovery remains authoritative for endpoint locations and currently advertised capabilities.
Principal lists and service access
Principal lists give consumer or tenant applications a membership and policy layer that can also include machine principals. A list defines selectable roles and a default role. Each bound application separately chooses whether newly issued access tokens include an active member’s role or data; both token-enrichment switches default off. Token claims are snapshots, while UserInfo and receiver ACL introspection can return current active membership fields.
- Create lists, manage members and configure application bindings
- List-backed token authorization
- Current membership through UserInfo
- Inbound machine-token ACL decisions
- Owner-controlled organization discovery
- PHP receiving-service guide
M7 can handle identity, list enrollment, policy decisions, and a shared expiring membership record for a consumer service. The receiving service still verifies sender-bound proof when required and enforces its own scopes and resource permissions. The PHP guide’s introspectAcl() API is included in the verified Token/PHP 0.1.4 ZIP.
Service capability discovery
Service capability catalogues describe exact actions and selectable bundles. This discovery is separate from OAuth and OpenID Connect endpoint discovery.
- Capability discovery and organization-member permission standard
- Blog service capability discovery JSON
The proposed M7 standard separates Management-role defaults (role.owner, role.admin, role.member), explicit service presets (preset.*), family bundles such as post.read and post.write, and exact actions such as post.save. Bundles expand to explicit, versioned action lists. readonly grants read capabilities and allows separately selected writes.
A catalogue does not grant membership, ownership, or resource access. Receiving services must verify direct organization Management membership, owner-permitted disclosure to the receiving registration, and the organization’s actual resource permissions. The guide separates the proposed contract from current implementation gaps, including Blog’s pending organization-selection enforcement and Writer’s published-post editing limitation.
M7 Identity SDK downloads
Published development-access PHP releases and the Browser Direct/JS 0.1.0 release:
| Package | Version | Downloads |
|---|---|---|
| Web/PHP | 0.1.4 | ZIP · SHA-256 · Manifest |
| Token/PHP | 0.1.4 | ZIP · SHA-256 · Manifest |
| CLI/PHP | 0.1.2 | ZIP · SHA-256 · Manifest |
| Browser Direct/JS | 0.1.0 | ZIP · SHA-256 · Manifest |
Verify each ZIP against its SHA-256 sidecar before extraction. CLI/PHP 0.1.2 requires Token/PHP >=0.1.3 <0.2.0; use the matching Token/PHP download above.
Browser Direct/JS 0.1.0 is tagged browser-direct-v0.1.0. Its public ZIP, SHA-256 sidecar, and manifest match the SDK release files. The owner reports that all browser-direct flows worked on HenryGoss.com on 2026-09-25. See the browser-direct guide for independent login, logout, signup, account, and token-status examples and the complete integration page.
M7 C Crypto and the compiled M7 PHP Crypto extension are optional dependencies for specific cryptographic features. Ordinary base SDK installation does not require them. See optional native runtime requirements.
Get started
- Install M7 Identity SDK for a website
- Use browser-direct JavaScript and its examples
- Install M7 Identity SDK for CLI and background processes
- Discover service capabilities and resolve organization permissions
The SDK packages are distributed under MTL-10. Packagist installation is not currently available.