Platform
Authentication
Managed Woven uses two separate authentication layers: Firebase identity for the Host control plane and an opaque, product-scoped Bearer credential for realtime client connections.
Host control plane
- Identity
- Firebase Authentication signs users in with Google, GitHub, or email. The control API verifies the Firebase ID token and resolves the account entitlement on protected requests.
- Recent authentication
- Revealing connection credentials and deleting an account require a Firebase sign-in completed within the previous five minutes. The web app reauthenticates the same account before the user explicitly retries the operation.
- App Check
- The current hosted deployment runs App Check in monitor mode: a supplied token is verified, while a missing token is observed rather than rejected. Required mode enforces a valid token on every request; emulator use disables App Check.
Managed runtime
When a managed product is provisioned, Host can reveal its native QUIC and browser WebTransport endpoints, namespace, session, and an opaque Bearer credential. This runtime-admission credential is scoped to that product generation; Firebase claims and individual product-user identity remain in the Host control plane. For the current browser path, it is one shared possession credential intended for trusted or internal clients—not an end-user identity token.
- Host storage
- Host stores the credential encrypted with AES-GCM in its private credential record, bound to the product generation. Credential reveal remains owner-authorized and recent-auth protected.
- Woven verification
- The managed Woven node stores a verifier for the opaque credential and grants access only to the provisioned namespace and session. The user's Firebase token remains in the Host control plane.
- Compromise response
- Any holder of the shared product-generation token can use its managed scope. Credential rotation and short-lived client grants are not implemented yet, so suspected compromise requires deleting and recreating the product to issue a new scope and credential.
Availability
Control-plane identity and runtime authentication are active for managed products across native QUIC and browser WebTransport. The TypeScript browser client is Online. Pro and Dedicated remain Preview.