Single sign-on (SSO) and MFA for 9 applications
One identity, a second factor and central revocation across 9 applications
Key figures
- unified applications
- 9
- verified roadmap deliverables
- 28
- rollbacks
- 0
Context
The applications relied on shared accounts, with no second factor protecting access. And without central revocation, there was no single place to withdraw someone's access.
My role
From design to operations, fully autonomously.
Solution
The Zitadel identity provider is self-hosted, with its own database, a gRPC reverse proxy, a dedicated tunnel, monitoring and backups. Applications use the OIDC Authorization Code + PKCE flow.
Tokens stay on the server; frontends only ever hold an opaque HttpOnly session with CSRF protection. A shared session client and a reusable BFF package mean the integration is never rewritten from scratch. For MFA, users choose between passkeys, TOTP or e-mail OTP.
Key features
One identity for 9 applications
A single sign-on replaces shared accounts, with central revocation.
MFA, your way
Passkeys, TOTP or e-mail OTP, depending on each user's preference.
No tokens in the browser
Frontends only hold an opaque HttpOnly session with CSRF protection.
Self-hosted identity provider
Zitadel with its own database, a gRPC reverse proxy, a dedicated tunnel, monitoring and backups.
Engineering challenges
- 1
Migration with no lost access
Existing password hashes were imported, and roles are projected into the tokens.
- 2
Single, reversible cutover
The API and 7 frontends switched over at once, the API moving to a shared subdomain.
- 3
Blockers fixed within the window
5 blocking defects were fixed during the cutover, with no rollback.
- 4
Identity configured through CI
IdP configuration is applied through CI only, and verified by identity contract tests.
Tech stack
- Security
- ZitadelOIDC/PKCEBFF
- Infrastructure
- TraefikNginxCloudflare TunnelPrometheusAlertmanager
- Data
- PostgreSQL
- Backend
- TypeScript
A project of this scale?
Let's talk about your context: I'll tell you frankly what is feasible, and how long it takes.