Aether Labs SSO
The central identity provider for every Aether Labs app — one login, one session, shared across the ecosystem.
Aether Labs SSO
Aether Labs SSO (also called Aether Labs Accounts) is the central identity
provider for the whole Aether Labs ecosystem — the "Google accounts" of Aether Labs.
Users authenticate and manage their account once, then move between Aether Labs apps
without signing in again. One identity store, one login, shared across every
*.aetherlabs.agency subdomain.
Every Aether Labs app — Admin, Website, and the products still to come — delegates login, registration, and session management to Aether Labs SSO instead of building its own.
Surfaces
| Surface | Production | Local dev | What it is |
|---|---|---|---|
| API | https://sso.aetherlabs.agency | http://localhost:4000 | Issues and verifies tokens. Every endpoint in these docs is relative to this base. |
Login / consent UI (accounts-web) | https://accounts.aetherlabs.agency | http://localhost:3001 | Where users sign in, register, and approve OAuth consent. |
Profile UI (myaccount-web) | https://myaccount.aetherlabs.agency | http://localhost:3002 | Users manage their own profile and security. |
SSO admin console (admin-web) | https://admin.sso.aetherlabs.agency | http://localhost:3003 | Internal console for users, roles, and OAuth clients. |
One API base URL
Every API call goes to a single base — for example
https://sso.aetherlabs.agency/api/auth/me. Local development uses
http://localhost:4000.
How it fits together
Any Aether Labs app ──redirect──▶ accounts.aetherlabs.agency (login / register)
▲ │ issues access + refresh tokens
└──────────redirect back────────┘
│
App backends verify tokens via sso.aetherlabs.agency
(local HS256 verification, or GET /api/auth/me).Aether Labs SSO owns:
- user registration and login
- the SSO session cookies (
accessToken,refreshToken) - the OAuth 2.0 authorization-code flow (PKCE required)
- access and refresh tokens (refresh tokens rotate)
- the OpenID
userinfoendpoint - roles and permissions (RBAC)
- OAuth client records
- the admin console
Two ways to integrate
Pick one based on where your app lives.
| Pattern | Use it when | Guide |
|---|---|---|
| First-party cookie SSO | Your app is an Aether Labs-owned app on the same parent domain (*.aetherlabs.agency). No OAuth client, no secret, no PKCE. | Same-domain SSO |
| OAuth client | Your app is third-party, lives on an unrelated domain, or needs an explicit consent screen. PKCE (S256) is required and the client authenticates with a secret. | OAuth integration |
Not sure which one? Getting Started walks through the decision.
Where to go next
- New here? Start with Getting Started.
- Building a first-party Aether Labs app? See Same-domain SSO.
- Integrating a third-party or standalone app? See OAuth integration.
- Registering an app? See OAuth clients.
- What a client may ask for: Scopes & tokens.
- Reviewing or revoking access: Connected apps.
- Roles, permissions, and the seeded roles? See Roles & permissions.
- Self-hosting the stack? See Deployment.
- Endpoint-by-endpoint details? See the API reference.