M7 Identity Architecture

Pre-launch preview Detailed architecture remains under release hold

The security model, without the launch playbook.

M7 Identity begins with OAuth 2.0 and OpenID Connect concepts, then adds M7-aware controls for renewable session authority, controlled refresh activation, and validation across application boundaries. This page summarizes the direction; release-level details remain intentionally withheld.

Safe public summary Architecture at a glance

Security follows the whole renewable session.

The visible login is only the beginning. M7 treats renewal, successor handoff, service validation, closure, and recovery as parts of one identity lifecycle.

  1. 01 Establish A valid login establishes authority for the primary human session.
  2. 02 Scope Renewable authority is carried through a named session lineage.
  3. 03 Confirm ACK can separate successor issuance from authorized activation.
  4. 04 Validate Applications and services enforce the supported identity contract at their boundaries.

02 / Disclosure boundary

Back to top

Pre-launch

Undisclosed until we are nearing launch.

M7 will publish enough architecture, threat-model, compatibility, and conformance material for serious evaluation. We are not publishing the complete launch playbook while the product is still being hardened.

01 Public now

The product direction.

The standards relationship, renewable-session focus, M7-aware integration boundary, and high-level lifecycle are safe to describe now.

02 Near launch

The evaluation package.

The named profile, detailed threat model, extension guide, SDK matrix, limitations, and conformance evidence will follow nearer release.

03 Held back

The implementation playbook.

Protocol-level decisions and differentiating implementation details remain private while release hardening is underway.