99.99% Uptime•All Systems Operational
Centralized Identity & Single Sign-On

Unified Identity & Single Sign-On (SSO) for OneXCC Network

Next-generation enterprise-grade Identity Provider (IdP). Multi-layered security seamlessly bridging personal developer identities and B2B organizational workspaces.

{
  "issuer": "https://iam.xcc.one",
  "authorization_endpoint": "https://iam.xcc.one/oauth2/authorize",
  "token_endpoint": "https://iam.xcc.one/api/auth/oauth2/token",
  "userinfo_endpoint": "https://iam.xcc.one/api/auth/oauth2/userinfo",
  "jwks_uri": "https://iam.xcc.one/.well-known/jwks.json",
  "response_types_supported": ["code"],
  "subject_types_supported": ["public"],
  "id_token_signing_alg_values_supported": ["RS256"],
  "code_challenge_methods_supported": ["S256"],
  "scopes_supported": ["openid", "profile", "email", "offline_access"]
}
Endpoint Live•200 OK
Technical Standards

Security Standards & Hardened Infrastructure

Every authentication and authorization transaction is protected by Zero Trust principles, adhering to rigorous modern cryptographic standards.

Federated Identity

OpenID Connect & OAuth 2.1

Full OIDC Core 1.0 compliance, standard Discovery Endpoint, and automatic RSA 2048-bit key rotation via JWKS Endpoint.

AUTHORIZATION CODE FLOW + JWKS KEY ROTATIONVerified
CLIENT APPOneXCC App
IDP SERVERXCC IAM Engine
SECURITY TOKENRSA-256 Signed
RFC 8707

RFC 8707 Resource Indicators & Audience Binding

Strict RFC 8707 compliance encoding target resource URIs into auth codes and binding access token JWT audience (aud) specifically to MCP hosts and satellite APIs, preventing cross-service token misuse.

aud: mcp-host.oneapp.io
Token scope: bound per resource
RFC 7636

PKCE S256 Code Challenge

Mandatory SHA-256 Proof Key for Code Exchange in all authorization code flows, eliminating authorization code interception on client apps.

Method: SHA-256
S256(verifier) → challenge
RFC 9106

Argon2id Password Hashing

State-of-the-art password hashing with high memory cost parameters, neutralizing GPU/ASIC hardware brute-force attacks.

Memory Hardness: High
GPU/ASIC Brute-Force Immune
Zero-Trust Runtime

Zero-Secret Container Runtime & Cloudflare Turnstile Protection

Isolated Docker container runtime with zero plaintext secrets, AES-256-GCM encrypted configuration files decrypted only in memory. Kết hợp công nghệ phát hiện bot thông minh Cloudflare Turnstile loại bỏ thử thách phiền phức cho người dùng.

CONFIG ENCRYPTIONAES-256-GCM In-Memory Only
BOT DEFENSENon-Interactive Invisible Defense
Operational Model

Dual-Track Identity: Personal & Enterprise

Clear segregation of duties between independent developer profiles and enterprise B2B workspaces.

Personal Identity

Personal Profile (Developer ID)

Built for developers, creators, and independent users

DV
[email protected]usr_94f8a2bc41d
Active
Sessions: 2 devicesPermissions: 4 granted
Universal single identity across all OneXCC apps and services
Self-service profile, avatar, and active session management
Multi-factor security, verified email credentials, and safe reset flows
Full visibility and revocable granular consent for third-party apps
B2B Multi-Tenancy

Enterprise Workspaces (B2B Multi-Tenancy)

Engineered for corporations, institutions, and teams

AC
Acme Corp HQorg_9918bc28a01
Verified Org
Members: 1,420SSO: SAML 2.0 Active
Organization provisioning, invite members via email or secure links
Strict Role-Based Access Control (Owner, Admin, Member)
Centralized Single Sign-On (SSO) for corporate staff and projects
Enterprise application clients, Client Credentials, and immutable Audit Logs