Overview
Use AccessGuard Bridge v2 and the site-side proxy/SDK for registration, login, refresh, recovery, verification, logout, and the customer-safe operations authorized for the active plan.
Problem
Multiple websites need one governed identity authority without exposing workspace secrets to browser code.
Solution
Keep the customer identity and security state in AccessGuard and let each website call scoped Bridge capabilities through a signed server-side proxy.
How it works
The external site receives authorized customer-safe operations while AccessGuard enforces credential scope, origin, replay, rate, identity, session, and resource policy.
Who is this for
Expected outcomes
- One authentication authority across connected sites
- Server-side credential protection with scoped Bridge operations
Key metrics
Security impact
- User identity, site credential, session/token state, profile and inbox operations · PII: yes for customer identity/profile and notification data
Compliance
- Bridge client authorization, HMAC request validation, replay/rate controls, and resource-scoped customer operations