Core flows · Identity and authority
One human identity, deployment-scoped credentials and isolated data
The hosted identity provider proves who a person is. Each gateway then issues its own revocable device credential and resolves that identity to a stable NeoStory principal without sharing graph or blob storage across deployments.
Core flows · Identity and authority
One human identity, deployment-scoped credentials and isolated data
The hosted identity provider proves who a person is. Each gateway then issues its own revocable device credential and resolves that identity to a stable NeoStory principal without sharing graph or blob storage across deployments.
What this view establishes
The architectural commitments
- The identity provider proves identity; it does not receive NeoStory graph or blob data.
- Native apps hold gateway credentials, not identity-provider secrets or database credentials.
- The web signs in through the same device leg a phone uses, with an https return address instead of a custom scheme; the credential lives in an encrypted HttpOnly cookie and every portal proxy reads as that person, falling back to the portal's own bearer only when nobody is signed in.
- Signed in is not let in: under the approval policy the gateway refuses a person nobody approved on every route but the sign-in surface, service credentials are never gated, and admins hold a per-deployment role — so a public web can stay hidden until each account is let in.
- Every app hosts the same sign-in surface from the package; an app's own part is its bundle configuration, its wording and two callbacks.
Trust-lane sequence
Identity
Resolution and credentials
Environment clients
Scoped authorities
Identity and credential sequence
Connections and evidence
Open the 10-relationship source key
Numbers set an explanatory reading order. They do not measure runtime timing.
Connections and evidence
Open the 10-relationship source key
- 01observed
Person→OIDC provider
signs in
- 02observed
OIDC provider→Device sign-in
callback
- 03implemented
Issuer + subject→Principal resolution
maps
- 04implemented
Device sign-in→Gateway credential
issues
- 05implemented
Principal resolution→Gateway credential
binds
- 06implemented
Gateway credential→Apple apps
stores
- 07implemented
Principal resolution→Web session
same identity model
- 08implemented
Apple apps→Graph authority
authorized API
- 09implemented
Apple apps→Blob authority
authorized media
- 10implemented
Web session→Graph authority
authorized API and media
Connections and evidence
10 directed, source-backed relationships
Numbers set an explanatory reading order. They do not measure runtime timing.
- 01observed
Person→OIDC provider
signs in
- 02observed
OIDC provider→Device sign-in
callback
- 03implemented
Issuer + subject→Principal resolution
maps
- 04implemented
Device sign-in→Gateway credential
issues
- 05implemented
Principal resolution→Gateway credential
binds
- 06implemented
Gateway credential→Apple apps
stores
- 07implemented
Principal resolution→Web session
same identity model
- 08implemented
Apple apps→Graph authority
authorized API
- 09implemented
Apple apps→Blob authority
authorized media
- 10implemented
Web session→Graph authority
authorized API and media
What this view establishes
The architectural commitments
- The identity provider proves identity; it does not receive NeoStory graph or blob data.
- Native apps hold gateway credentials, not identity-provider secrets or database credentials.
- The web signs in through the same device leg a phone uses, with an https return address instead of a custom scheme; the credential lives in an encrypted HttpOnly cookie and every portal proxy reads as that person, falling back to the portal's own bearer only when nobody is signed in.
- Signed in is not let in: under the approval policy the gateway refuses a person nobody approved on every route but the sign-in surface, service credentials are never gated, and admins hold a per-deployment role — so a public web can stay hidden until each account is let in.
- Every app hosts the same sign-in surface from the package; an app's own part is its bundle configuration, its wording and two callbacks.
Follow the live system
Move from explanation to inspection
The Atlas is static and source-backed. The Observatory shows authenticated environment state.
19 repository sources behind this view
Explorer/app/api/blob-resources/[id]/content/route.tsExplorer/app/api/library/_authority.tsExplorer/app/api/session/return/route.tsExplorer/app/api/session/sign-in/route.tsExplorer/app/lib/session.server.tsREADME.mdSources/NeoStoryClient/CredentialStore.swiftSources/NeoStoryClientUI/AuthoritySignInCoordinator.swiftSources/NeoStoryHTTP/HTTPAuthorityTransport.swiftSources/NeoStoryHTTP/HTTPBlobClient.swiftdocs/access-scopes.mddocs/delegation/login-results-2026-09-02.mddocs/delegation/sign-in-surface-results-2026-09-03.mddocs/delegation/web-session-playback-results-2026-09-08.mddocs/deployment.mddocs/login-owner-decisions-2026-09-02.mdgateway/README.mdgateway/src/neostory_gateway/device_sign_in.pygateway/src/neostory_gateway/oidc_login.py