Project
7saberid
Identity provider for the 7Saber ecosystem — the service behind a 'Sign in with 7SaberID' button, the way Google sits behind 'Sign in with Google'. It is not a social-login wrapper: the only credentials it accepts are its own, phone plus OTP for customers and email plus password for staff. One account spans storefront web, mobile, the admin portal, mini apps and unit-owned systems. It holds its own database and JWKS, so resource servers keep verifying already-issued tokens even while the service itself is down.
OpenID Connect provider
Two credential doors: phone+OTP for customers, email+password for staff
RS256 signing with published JWKS
Resource servers keep verifying tokens during provider downtime
Role assignments and session records per account
Admin console for identity operations