Cloud services · AppID

Add sign-in to your app by setting one field.

Deploy your app with a user pool and the gateway handles the entire browser login before your code runs — the hosted page, the redirect, the session cookie, the refresh. Your app ships no login page, no /auth routes and no session handling. It reads a header.

Three commands

This is the entire integration.

A pool is the unit of app identity. Connections are how people get in. The deploy flag points your app at the pool — and from that moment the gateway is doing the work.

# a pool is the unit of app identity
dodil appid pool create --group crm-suite

# how people get in
dodil appid connection add local         --pool crm-suite
dodil appid connection add oauth:google  --pool crm-suite \
  --client-id … --client-secret …

# point the app at it — this is the whole integration
dodil ignite app deploy crm-core --auth pool:crm-suite
Connections

Turn on Google. That's the whole task.

Paste a client id and secret, flip the toggle. No redeploy, no library, no callback route in your app — the hosted login picks it up on the next sign-in.

Connectionscrm-suite
Email and passwordargon2id · verify email
Googleoauth · client configured
GitHubneeds client id
Microsoftneeds client id
Any OIDC providerdiscovery URL
The page your users seehosted · branded
Sign in to Acme CRM
••••••••••
Continue
or
Continue with Google
Forgot your password?
Users

Everyone who signed up, in one list.

Invite someone, reset a password, assign a role, ban an account. Revoking sessions signs that person out of every app in the pool at once.

App users1,284 total · live
[email protected]googleagent2m ago
[email protected]passwordadmin41m ago
[email protected]googleagent · viewer3h ago
[email protected]oidcviewer1d ago
[email protected]password—banned
Roles

Define them once. Read them off the token.

Role catalogcrm-suite
adminread · write · manage-users · billing
agentread · write
viewerread
What your app receivesevery request
X-Dodil-User:
  {"sub":"au_9f2c…",
   "email":"[email protected]",
   "connection":"oauth:google",
   "app_roles":["agent"]}

X-Dodil-User-Jwt: eyJhbGciOiJFZERTQSIs…
Trust the edge, or verify the JWT yourself against the pool's JWKS.
Handled at the edge

The parts nobody enjoys writing.

Your app ships none of thisgateway
Hosted login pagebranded, served for you
PKCE S256 · state · nonceredirect-URI allowlist enforced
Session cookiessealed, http-only, host-scoped
Token refreshsingle-flight, rotating, reuse-detected
Password reset and email verificationrequest, email, reset page
Cross-app SSOone login for every app in the pool
Sign-outend-session clears it everywhere
A separate plane, on purpose

Your app's users are not your Dodil users.

Your Dodil account is a platform principal — it can touch buckets, repos and deploys. The people who use the app you built live in their own pool, with their own issuer and their own signing keys. The two never share an issuer, and a platform grant can never arrive inside an app token. Your customers signing up does not widen your blast radius.

Two things worth knowing
  • An app scaled to zero cold-starts on the first login redirect — an image pull and a boot, so seconds. The hosted page holds its “Signing you in…” state throughout, but pin the app warm if that pause matters to you.
  • Dedicated SAML for corporate SSO is built but not yet enabled; it is reserved for the enterprise tier. Generic OIDC works today and covers most providers.
FAQ

Questions, answered.

Your users are one flag away.

Create a pool, add a connection, deploy with --auth pool:…

Start free
Regions
UKLiveEULiveMiddle EastSoonAfricaSoon
Compliance
SOC 2In progressISO 27001In progressGDPR-readyData residencyEnforced
© 2026 Circle Technologies Pte Ltd. All rights reserved.