DEMO · labelled fixtures · no authoritative writes
Local control plane·Actions persist on this device. Set NEXT_PUBLIC_API_BASE and NEXT_PUBLIC_SKYFORGE_API_BASE for the live identity, billing and SS-47 APIs.
Trial · 7d left
Demo operatorskyforge-demo

Profile

Identity profile

SkyForge reads this identity from the authenticated session and does not maintain a second user directory.

Identity-managed
Operator

Full name
Operator
Email
Tenant
Username

Name, email, password and MFA changes belong to the configured StratoID / Authentik authority. SkyForge deliberately refuses to show a successful local edit when no authoritative identity mutation has occurred.

Account security boundary

What SkyForge owns versus what the identity platform owns.

  • SkyForge: application roles, tenant-scoped API keys, session visibility, audit evidence and control-plane authorization.
  • Identity authority: passwords, MFA factors, primary email, recovery, federation and account lifecycle.
  • Platform policy: SpiceDB / authorization decisions remain deny-by-default for protected operations.