AETHERLABS

Aether Labs SSO

The central identity provider for every Aether Labs app — one login, one session, shared across the ecosystem.

Aether Labs SSO

Aether Labs SSO (also called Aether Labs Accounts) is the central identity provider for the whole Aether Labs ecosystem — the "Google accounts" of Aether Labs. Users authenticate and manage their account once, then move between Aether Labs apps without signing in again. One identity store, one login, shared across every *.aetherlabs.agency subdomain.

Every Aether Labs app — Admin, Website, and the products still to come — delegates login, registration, and session management to Aether Labs SSO instead of building its own.

Surfaces

SurfaceProductionLocal devWhat it is
APIhttps://sso.aetherlabs.agencyhttp://localhost:4000Issues and verifies tokens. Every endpoint in these docs is relative to this base.
Login / consent UI (accounts-web)https://accounts.aetherlabs.agencyhttp://localhost:3001Where users sign in, register, and approve OAuth consent.
Profile UI (myaccount-web)https://myaccount.aetherlabs.agencyhttp://localhost:3002Users manage their own profile and security.
SSO admin console (admin-web)https://admin.sso.aetherlabs.agencyhttp://localhost:3003Internal console for users, roles, and OAuth clients.

One API base URL

Every API call goes to a single base — for example https://sso.aetherlabs.agency/api/auth/me. Local development uses http://localhost:4000.

How it fits together

  Any Aether Labs app  ──redirect──▶  accounts.aetherlabs.agency  (login / register)
       ▲                               │ issues access + refresh tokens
       └──────────redirect back────────┘
                                        │
  App backends verify tokens via sso.aetherlabs.agency
  (local HS256 verification, or GET /api/auth/me).

Aether Labs SSO owns:

  • user registration and login
  • the SSO session cookies (accessToken, refreshToken)
  • the OAuth 2.0 authorization-code flow (PKCE required)
  • access and refresh tokens (refresh tokens rotate)
  • the OpenID userinfo endpoint
  • roles and permissions (RBAC)
  • OAuth client records
  • the admin console

Two ways to integrate

Pick one based on where your app lives.

PatternUse it whenGuide
First-party cookie SSOYour app is an Aether Labs-owned app on the same parent domain (*.aetherlabs.agency). No OAuth client, no secret, no PKCE.Same-domain SSO
OAuth clientYour app is third-party, lives on an unrelated domain, or needs an explicit consent screen. PKCE (S256) is required and the client authenticates with a secret.OAuth integration

Not sure which one? Getting Started walks through the decision.

Where to go next

On this page