One access layer
Give people a consistent sign-in path across approved applications instead of creating a separate identity island for every product.
Early access · expressions of interest open
1App is a new identity and access layer designed to make secure access simpler for people, organisations and the applications they rely on — starting with the Alphareon ecosystem and built to grow beyond it.
Continue securely to your organisation and approved applications.
Identity without the sprawl
1App is being designed as a shared identity plane: one place to authenticate people, understand which organisation and application they belong to, and hand trusted context to the product that actually does the work.
Give people a consistent sign-in path across approved applications instead of creating a separate identity island for every product.
Keep canonical identity, organisation membership and application access explicit rather than inferring identity from mutable email addresses.
Apply MFA and bounded session policy at the identity layer, with stronger limits available for privileged access.
Build around OIDC, OAuth and mature identity infrastructure so applications can integrate without proprietary cookie sharing.
1App answers who the actor is and what identity-level access they have. The relying product keeps ownership of its operational work.
Start with the secure foundation already being proven for Logicl, then add federation, passkeys and broader administration only as they are ready.
1App is built to be an identity gateway. It does not need to own each product's business data, workflow or UI.
Canonical 1App identity is deliberately separate from email so account identity does not depend on a mutable contact field.
Organisation and application context are designed to be revalidated rather than copied into indefinite browser sessions.
Trust is part of the product
1App is early, so the public promise stays narrower than the architecture. We describe what is implemented, and keep future capability clearly labelled as future.
Identity security gets weaker when convenience shortcuts quietly become permanent access. 1App's current foundation keeps application sessions bounded, separates normal and privileged policy, and requires fresh authentication again when the absolute limit is reached.
For product and platform teams
1App is being shaped around standards and mature open-source foundations so the differentiated work can stay focused on organisations, application access, assurance and a better operating experience.
identity { protocol: "OIDC" flow: "Authorization Code + PKCE" identity_key: "canonical 1App ID" } context { organisation: explicit membership application: explicit access assurance: bounded session policy }
The current identity engine is Keycloak. 1App layers a stable product contract around it rather than exposing raw provider internals as the downstream identity model.
Logicl is the first real relying application, proving the migration pattern while preserving Logicl's existing application-session and tenant boundaries during the first stage.
Help shape what comes next
1App is not commercially available yet. We are collecting expressions of interest to understand where identity friction is costing organisations time, deals or confidence — and which use cases should shape the next product milestones.
Questions
No. 1App is an early-stage identity platform. The site is collecting expressions of interest while the product foundation and first relying-application integration are being proven.
No. The current product direction is identity and access infrastructure: authentication, MFA, sessions, organisation membership, application access and standards-based SSO.
No. 1App owns identity-plane access. In the Alphareon architecture, governed business-action policy belongs to Sentinel rather than being mixed into authentication.
No. A relying application can keep its own application session, tenant data and operational permissions while using 1App as the authentication and identity authority.
TOTP is the initial MFA method in the current foundation. Passkeys/WebAuthn and broader federation are future directions and are not represented as launched features.