Skip to content

Identity and Access

DragonPay's Auth0 usage is workforce/operational identity only — P2P senders and recipients never authenticate through it. They enter the Product flow through their credit union's own digital-banking session (PH-01's trusted authentication context) or the hosted Recipient claim experience (CX-01). Auth0 authenticates DragonPay staff and CU operations staff who use the Ops console (OX-01) and DragonPay's own APIs.

Current-lean technology (DR-017, open — ENG-01 §4), reflecting the parent PE company's shared platform stack. Integration pattern is ENG01-24's deliverable; the specific pattern described (BFF, guard chain, no Auth0 Organizations) is contingent on this lean being confirmed — not yet built, not yet decided, no ADR recorded.

Auth0

ENG01-24's deliverable. Not yet built.

Authentication

Governed by ENG01-24 and PH01-02 (Establish Trusted Caller Context) once built.

Authorization

Governed by ENG01-24 and PH01-03 (Assign and Enforce Access) once built.

Roles

PH01-03 requires DragonPay to support the initial platform and Tenant-scoped role catalog. Not yet built.

Permissions

PH01-03 governs permission assignment. Not yet built.

Enforcement

ENG01-24's deliverable — not yet built. (The specific guard chain, token-handling, and baseline security-control choices described in an earlier draft of this page were implementation detail with no ADR or code behind it; they'll come back once ENG01-24 is actually implemented.)