Authorisation
Auth
AvailableAnswers “may user X do Y” over HTTP.
Auth answers one question over HTTP: may user X do Y. It handles authorisation only. It does not sign anyone in, store passwords, issue tokens or manage sessions, and it relies on the caller to know who the user is. The model is users, roles and permissions: a user holds a permission exactly when one of their roles holds it.
Who it is for. Services that need role-based access control and do not want to maintain their own roles and permissions tables.
- Status
- Available
- Part of
- Core platform
- Product site
- auth.rodmena.app
- Tags
- Access controlRoles and permissionsOne decision
What it does
-
One question
The whole API answers “may user X do Y”, consistently for every service.
-
Users, roles, permissions
Membership of a role grants its permissions, with nothing else to model.
-
Authorisation only
Passwords, sessions and tokens are out of scope and belong to RODMENA ID.
-
Quick to adopt
One call, one answer, and a response shape that is fixed, so a service can be brought under central access control in an afternoon.
Documentation and access details are on the product site, auth.rodmena.app. For a pilot, an integration or procurement questions, contact us.