Enterprise identity infrastructure

One identity for every app —
Share the same User identity

Auth-One is a unified identity platform built on Golang and PostgreSQL. It includes authentication, RBAC, organization structure, multi-app authorization, and third-party login, and connects to any system through a REST API.

JWT authentication bcrypt password hashing Rate limiting Complete audit logs
POST /api/v1/auth/login200 OK

// Request body

{
  "username": "admin",
  "password": "••••••••"
}

// Response

{
  "token": "eyJhbGciOiJIUzI1NiIs…",
  "expires_at": "2026-08-14T07:48:00+08:00",
  "user": { "username": "admin", "status": "active" }
}

One platform for the entire identity lifecycle

From sign-up and login to access control, third-party integration, and audit logs, Auth-One provides complete capabilities out of the box.

User management

Registration, sign-in, and profile management with passwords securely hashed using bcrypt.

RBAC permission model

A complete role and permission system with fine-grained access control.

Organization

Hierarchical department and position management for real-world organizations.

Multi-application authorization

User-application permission management, one account can access all applications.

Third-party sign-in

Link third-party accounts such as WeChat, QQ, and GitHub.

API integration management

AppID / APIKey / Secret credentials with API-level permissions and rate limiting.

Audit trail

Record complete audit logs, including request and response parameters.

Data integrity

Hash verification protects critical data from tampering.

Integrate in three steps

Open APIs for third-party systems use client credentials, so you can complete the first request in minutes.

01

Submit integration request

Fill in the project information and access purpose, enter the review queue after submission, and the results will be available in 1-3 working days.

POST /api/v1/access-requests
02

Receive client credentials

After passing the review, the administrator will create an API client for you and deliver the AppID, APIKey and Secret.

X-App-ID / X-API-Key / X-Signature
03

Call public APIs

Securely access open data such as users and applications based on application and interface permissions.

GET /api/v1/external/users/{id}

Mature and reliable technology stack

Built on mainstream components with no heavy dependencies, making it easy to deploy and extend.

Gin v1.11PostgreSQL 14+pgx v5 + sqlcJWT (golang-jwt/v5)Zap loggingbcrypt + SHA256Redis rate limitingDocker deployment

Ready to integrate Auth-One?

Submit an access request to get API credentials, or read the docs and run your first request.