On-network first
Challenge–response between the Rune agent, your IdP, and Saga on the LAN. Everyday suite access does not require a multi-tenant SaaS identity hop.
ᚱ · Rune Token · suite core
Rune Token roots identity in the workstation you trust. Saga and every suite app open as the same person — no public-cloud identity landlord.
Mark: ᚱ. Offline-capable. Device proofs. Suite SSO without secrets in the page. Yours.
User authenticates at the site IdP (device trust and/or OTP).
Required console mints app-scoped suite activation.
Stella, Thala, and other RPs receive HttpOnly BFF cookies — same person, app-scoped rights.
Sensitive actions use short-lived server sessions — secrets are not left in browser JavaScript.
Built for sites that must work when the link is slow, locked, or gone. Keys on metal you control.
Challenge–response between the Rune agent, your IdP, and Saga on the LAN. Everyday suite access does not require a multi-tenant SaaS identity hop.
Ed25519 device proofs bind sessions to hardware the organisation already provisioned. Email OTP remains a fallback — not the only path.
After Rune unlocks the person, app-scoped BFF cookies open Stella, Thala, Skjal, and Skarð. Sensitive work stays in short-lived server sessions.
National-scale eID proved the model. We may go further: hardware-rooted, offline-capable attestation for high-assurance fleets.
TPM 2.0 / secure enclave binding, FIDO2 passkeys, measured boot — identity lives in silicon you control, not a SaaS directory.
Hybrid classical + ML-DSA / SLH-DSA signatures and CRYSTALS-Kyber key exchange — crypto agility baked in before harvest-now-decrypt-later becomes urgent.
Prove role, clearance, or fleet membership with zero-knowledge proofs on air-gapped Stella nodes — no PII broadcast, no central verifier required.
Issuance and CRL sync across your Thala fleet over LAN-only channels — instant lockout without internet, without trusting a third-party OCSP.
DeviceAnchor — TPM EK hash, measured boot PCRs, optional FIDO2 cred binding.
HybridKeyPair — ML-DSA / SLH-DSA + classical agility interfaces.
ZkAttestor — offline membership proofs for fleet and clearance claims.
RevocationMesh — LAN CRL sync target for Thala fleet distribution.
Phase 1 live: suite sign-in and short-lived operator sessions. Rune agent for air-gap device login. Phase 2 roadmap: hardware bind options — not required for current SKUs.