Layer 01 · Identity & Security
Every user, session, and secret through one identity model
Secure every user, session, and secret through one canonical identity model. Conflux handles authentication, authorization, credential storage, and audit trails as native platform modules — not bolt-on libraries each developer wires differently.
Why this layer
Built into the platform, not bolted on
Every module in this layer solves the same class of problem the same way — regardless of who implements it.
01
No auth stack assembly
Skip the OAuth provider matrix, JWT library debates, and RBAC frameworks. Auth, authorization, secrets, and audit ship as platform modules with one SDK surface.
02
Same output from every author
A junior developer, a senior engineer, and an AI agent all integrate sign-in the same way. Session handling, token refresh, and policy checks follow one canonical path.
03
Compliance-ready by default
Immutable audit logs, encrypted secrets, and policy enforcement at API boundaries — built into the layer, not added after the fact for enterprise deals.
Canonical implementation
One path for every author
Junior developers, senior engineers, and AI agents produce the same standard output.
How Conflux does it
One path for identity across your entire stack
Each capability in this layer exposes exactly one SDK method, one CLI command, and one config shape. The platform compensates for uneven technical competency — implementation variance is removed.
Canonical path
conflux.auth.signIn() — not three different OAuth wrappers
Policies defined once, enforced at SDK and API boundaries
Secrets injected at runtime — never committed to source
Audit events emitted automatically on auth and admin actions
What you get
Ship sign-in and access control without evaluating vendors
Onboard developers without tribal auth knowledge
Pass security reviews with platform-native audit and secrets
Extend policies across every app in the tenant from one registry
01 · Identity & Security
Sign-in that works the same everywhere
Email, phone OTP, and social providers through one SDK. Session management, token refresh, and MFA are platform defaults — not libraries each developer wires differently.
Auth · One canonical path
SDK
await conflux.auth.signIn({ provider: 'email' })CLI
conflux auth providers list
Config
auth: providers: [email, phone, google]
What's possible with Auth
01
Email, phone OTP, and social sign-in through one SDK
02
Session management with offline-aware token refresh
03
Multi-factor authentication as a platform toggle
03 · Identity & Security
Credentials that never touch source code
Encrypted vault storage with rotation, environment scoping, and runtime injection. Secrets are platform-managed — not scattered across .env files and CI variables.
Secrets · One canonical path
SDK
await conflux.secrets.get('stripe-key')CLI
conflux secrets set stripe-key
Config
secrets: rotation: 90d
What's possible with Secrets
01
Encrypted credential storage with rotation support
02
Environment-scoped secrets injected at runtime
03
No secrets in source code — one vault per deployment
04 · Identity & Security
Every action recorded, queryable, exportable
Immutable activity logs across auth, data, and admin operations. Built for debugging today and compliance reviews tomorrow — without bolting on a separate audit product.
Audit · One canonical path
SDK
await conflux.audit.query({ actor, since })CLI
conflux audit export --format json
Config
audit: retention: 365d
What's possible with Audit
01
Immutable activity logs for compliance and debugging
02
Queryable audit trail across auth, data, and admin actions
03
Export-ready formats for regulated environments
Explore
Continue through the platform
Nine layers, one cohesive stack. Browse adjacent layers or return to the full registry.