Early access · expressions of interest open

One identity.
Across your applications.

1App is a new identity and access layer designed to make secure access simpler for people, organisations and the applications they rely on — starting with the Alphareon ecosystem and built to grow beyond it.

Standards-first architecture Bounded sessions MFA foundation
Built for a modern identity stack
OIDC + PKCE
Canonical identity
Organisation context
Revocable sessions

Identity without the sprawl

Stop rebuilding access for every product.

1App is being designed as a shared identity plane: one place to authenticate people, understand which organisation and application they belong to, and hand trusted context to the product that actually does the work.

01

One access layer

Give people a consistent sign-in path across approved applications instead of creating a separate identity island for every product.

02

Organisation-aware identity

Keep canonical identity, organisation membership and application access explicit rather than inferring identity from mutable email addresses.

03

Authentication assurance

Apply MFA and bounded session policy at the identity layer, with stronger limits available for privileged access.

04

Standards-first integration

Build around OIDC, OAuth and mature identity infrastructure so applications can integrate without proprietary cookie sharing.

05

Clear application boundaries

1App answers who the actor is and what identity-level access they have. The relying product keeps ownership of its operational work.

06

Designed to extend

Start with the secure foundation already being proven for Logicl, then add federation, passkeys and broader administration only as they are ready.

1
Authenticate
Central 1App identity service
assured
2
Resolve context
Identity, organisation, application
explicit
3
Continue to product
Standards-based relying application
bounded

Centralise identity, not every application.

1App is built to be an identity gateway. It does not need to own each product's business data, workflow or UI.

Keep identities stable as details change.

Canonical 1App identity is deliberately separate from email so account identity does not depend on a mutable contact field.

Make access revocable.

Organisation and application context are designed to be revalidated rather than copied into indefinite browser sessions.

Trust is part of the product

Security boundaries you can explain.

1App is early, so the public promise stays narrower than the architecture. We describe what is implemented, and keep future capability clearly labelled as future.

Full authenticationCurrent foundation: password + TOTP
Standard session30 min idle · 12 hr absolute
Privileged session15 min idle · 8 hr absolute
Absolute expiryFresh full authentication required
Browser clientNo offline access
Future directionPasskeys / broader federation

Secure access without pretending every risk is the same.

Identity security gets weaker when convenience shortcuts quietly become permanent access. 1App's current foundation keeps application sessions bounded, separates normal and privileged policy, and requires fresh authentication again when the absolute limit is reached.

Server-enforced application session limits.
OIDC Authorization Code flow with PKCE, state and nonce.
Explicit issuer and relying-application boundaries.
No claim that 1App itself is OpenID, ISO, SOC 2 or IRAP certified before it actually is.

For product and platform teams

Integrate identity without inheriting an identity project.

1App is being shaped around standards and mature open-source foundations so the differentiated work can stay focused on organisations, application access, assurance and a better operating experience.

identity {
  protocol: "OIDC"
  flow: "Authorization Code + PKCE"
  identity_key: "canonical 1App ID"
}

context {
  organisation: explicit membership
  application: explicit access
  assurance: bounded session policy
}

Reuse the standards. Differentiate the experience.

The current identity engine is Keycloak. 1App layers a stable product contract around it rather than exposing raw provider internals as the downstream identity model.

Logicl is the first real relying application, proving the migration pattern while preserving Logicl's existing application-session and tenant boundaries during the first stage.

OIDCOAuth 2.0PKCEKeycloak foundationOrganisation contextMFA

Help shape what comes next

Interested in a simpler identity layer?

1App is not commercially available yet. We are collecting expressions of interest to understand where identity friction is costing organisations time, deals or confidence — and which use cases should shape the next product milestones.

Tell us where your current sign-in or access model creates friction.
Register interest in early design-partner or pilot conversations.
No account is created from this form and no commercial commitment is implied.

Register your interest

Short form. We only ask for enough information to understand the opportunity and contact you about 1App.

This form does not create a 1App account or canonical identity. See the privacy notice for this early-access form.

Questions

What 1App is — and is not.

Is 1App available to buy today?

No. 1App is an early-stage identity platform. The site is collecting expressions of interest while the product foundation and first relying-application integration are being proven.

Is 1App just another password manager?

No. The current product direction is identity and access infrastructure: authentication, MFA, sessions, organisation membership, application access and standards-based SSO.

Is 1App the business-approval or compliance engine?

No. 1App owns identity-plane access. In the Alphareon architecture, governed business-action policy belongs to Sentinel rather than being mixed into authentication.

Does 1App replace each application's own data model?

No. A relying application can keep its own application session, tenant data and operational permissions while using 1App as the authentication and identity authority.

What authentication methods will be supported?

TOTP is the initial MFA method in the current foundation. Passkeys/WebAuthn and broader federation are future directions and are not represented as launched features.