Identity infrastructure for your products

One identity layer.
Every product.

Perminister brings shared identity, product-scoped permissions, and API-key lifecycle into one service—while each app keeps its own portal and its own data.

An early product preview · Account and integration flows are not connected yet

One shared service

A common identity layer

Concept
Person / accountStarts from a consumer app

Identity and credential check

Perminister.
Identity and access serviceCentralized by Perminister
Identity & credentialsHuman session checksScoped permissionsAPI keys

Scoped identity and access decisions

Consumer applicationsConceptual
Consumer app
Consumer app
Consumer app

Each keeps its own portal, app session, domain data, and resource enforcement.

Conceptual boundary · no live app connection

Private by designSpaces credentials stay on the server. Product apps never access the bucket.

Clear boundary

Perminister provides identity and grants; each consumer app keeps its portal, session, data, and resource enforcement.

No connected-app data is loaded

A shared foundation

One identity. Clear boundaries.

Give consumer applications a consistent way to identify people and request scoped access, without moving their domain data into Perminister.

Identity with intent

Stable global identities can connect legacy accounts through an explicit, verified linking flow—not an email match.

Access in context

Grants carry a product and resource scope. Each app continues to enforce access against its own projects or workspaces.

Keys with a lifecycle

Scoped machine credentials are designed for rotation and revocation, with only a one-way verifier stored in Perminister.

Built around your app

Shared identity.
Product-owned access.

Perminister is a standalone identity and permission service. Each consumer application remains the place people start and the system that understands its own data.

  • Portals stay familiar to users
  • App data and resource checks stay in each product
  • Spaces is the only planned persistence layer

See what’s ready—and what isn’t.

The dashboard and developer guide distinguish current foundation from planned flows.

Read the developer guide