One account for all internal services. Sign in once with Google — connected apps receive a signed token, and your access follows your teams and roles.
Google sign-in
Authentication with your corporate Google account over OAuth 2.0 with PKCE. No passwords are stored here.
Roles & grants
Fine-grained access control: grants scoped to self, team or org, bundled into roles and assigned per team.
OAuth applications
Connected services get signed JWT tokens on their registered redirect URIs and verify them via the SSO API.
API keys
Personal sk_ keys for programmatic access to the API on behalf of your account — created and revoked here.