Your customers.
Their own accounts.
Add passkey sign-in and separate customer records to your app. Start with app-managed data for ordinary apps and preferences. Choose customer-private encryption when your app needs content hidden from its operator.
Preview availability
The client and server implementation are in preview. Hosted activation is a separate deployment step: check Auth health before integrating. A missing route or 503 means it is not enabled. Do not create stores to check availability. Use non-sensitive test data only.
Two choices. Explicit from the start.
App-managed · Recommended
The service manages encryption and enforces per-customer access. Authorised support tools can read one customer's data using temporary, audited access.
Customers sign in on another device without importing a data key. The service can decrypt content; this is not end-to-end encryption.
Customer-private · Advanced
Each customer's device encrypts their data. You cannot open it for support without their help.
On another device, they sign in and unlock with a private recovery file or an existing device. A passkey reset cannot replace a lost data key.
The agent sets it up. Customers sign themselves in.
Your agent registers an app, chooses its mode and proves control of its exact callback deployment. Only a public app ID goes into your browser app. Your agent can complete the first build without a developer vault account, email-provider setup or manual encryption keys. Customer registration requires no developer approval. Use the automatic setup helper in the integration guide.
Customers use their device's passkey prompt. The service derives record ownership from their verified session, so requests cannot choose another customer. Existing records never silently switch modes.
Support and recovery, with boundaries.
App-managed support access is read-only, limited to one account and expires after 15 minutes. Developers can revoke it and inspect audit events. After verifying a customer, the operator can issue a single-use passkey-reset link. The customer registers a replacement passkey; old passkeys and sessions are revoked. This preview does not send reset emails or verify customer email addresses.
Customer-private accounts keep account recovery separate from data-key recovery. Neither mode includes a staff dashboard, arbitrary permission-policy language or automatic conversion from a Connect store.
Still need simple account-free storage?
Connect remains useful for personal tools without customer accounts. Its share links grant store access; they are not a sign-in system. The Node SDK remains available for trusted backends.
Small by design.
The Auth preview has separate limits: 50 apps, 100 accounts per app, 1,000 accounts overall, 100 records and 1 MB per account, and 100 MB aggregate stored data. These are implementation limits, not a capacity benchmark. Read the guide for expiry, recovery and deployment requirements.