All projects
Security

Single sign-on (SSO) and MFA for 9 applications

One identity, a second factor and central revocation across 9 applications

Key figures

unified applications
9
verified roadmap deliverables
28
rollbacks
0

Context

The applications relied on shared accounts, with no second factor protecting access. And without central revocation, there was no single place to withdraw someone's access.

My role

From design to operations, fully autonomously.

Solution

The Zitadel identity provider is self-hosted, with its own database, a gRPC reverse proxy, a dedicated tunnel, monitoring and backups. Applications use the OIDC Authorization Code + PKCE flow.

Tokens stay on the server; frontends only ever hold an opaque HttpOnly session with CSRF protection. A shared session client and a reusable BFF package mean the integration is never rewritten from scratch. For MFA, users choose between passkeys, TOTP or e-mail OTP.

Key features

  • One identity for 9 applications

    A single sign-on replaces shared accounts, with central revocation.

  • MFA, your way

    Passkeys, TOTP or e-mail OTP, depending on each user's preference.

  • No tokens in the browser

    Frontends only hold an opaque HttpOnly session with CSRF protection.

  • Self-hosted identity provider

    Zitadel with its own database, a gRPC reverse proxy, a dedicated tunnel, monitoring and backups.

Engineering challenges

  1. 1

    Migration with no lost access

    Existing password hashes were imported, and roles are projected into the tokens.

  2. 2

    Single, reversible cutover

    The API and 7 frontends switched over at once, the API moving to a shared subdomain.

  3. 3

    Blockers fixed within the window

    5 blocking defects were fixed during the cutover, with no rollback.

  4. 4

    Identity configured through CI

    IdP configuration is applied through CI only, and verified by identity contract tests.

Tech stack

Security
ZitadelOIDC/PKCEBFF
Infrastructure
TraefikNginxCloudflare TunnelPrometheusAlertmanager
Data
PostgreSQL
Backend
TypeScript

A project of this scale?

Let's talk about your context: I'll tell you frankly what is feasible, and how long it takes.