Docs / Platform

Platform

Authentication

Managed Woven uses two separate authentication layers: Firebase identity for the Host control plane and an opaque, product-scoped Bearer credential for realtime client connections.

Host control plane

Identity
Firebase Authentication signs users in with Google, GitHub, or email. The control API verifies the Firebase ID token and resolves the account entitlement on protected requests.
Recent authentication
Revealing connection credentials and deleting an account require a Firebase sign-in completed within the previous five minutes. The web app reauthenticates the same account before the user explicitly retries the operation.
App Check
The current hosted deployment runs App Check in monitor mode: a supplied token is verified, while a missing token is observed rather than rejected. Required mode enforces a valid token on every request; emulator use disables App Check.

Managed runtime

When a managed product is provisioned, Host can reveal its native QUIC and browser WebTransport endpoints, namespace, session, and an opaque Bearer credential. This runtime-admission credential is scoped to that product generation; Firebase claims and individual product-user identity remain in the Host control plane. For the current browser path, it is one shared possession credential intended for trusted or internal clients—not an end-user identity token.

Host storage
Host stores the credential encrypted with AES-GCM in its private credential record, bound to the product generation. Credential reveal remains owner-authorized and recent-auth protected.
Woven verification
The managed Woven node stores a verifier for the opaque credential and grants access only to the provisioned namespace and session. The user's Firebase token remains in the Host control plane.
Compromise response
Any holder of the shared product-generation token can use its managed scope. Credential rotation and short-lived client grants are not implemented yet, so suspected compromise requires deleting and recreating the product to issue a new scope and credential.

Availability

Control-plane identity and runtime authentication are active for managed products across native QUIC and browser WebTransport. The TypeScript browser client is Online. Pro and Dedicated remain Preview.