Deploy your app with a user pool and the gateway handles the entire browser login before your code runs — the hosted page, the redirect, the session cookie, the refresh. Your app ships no login page, no /auth routes and no session handling. It reads a header.
A pool is the unit of app identity. Connections are how people get in. The deploy flag points your app at the pool — and from that moment the gateway is doing the work.
# a pool is the unit of app identity
dodil appid pool create --group crm-suite
# how people get in
dodil appid connection add local --pool crm-suite
dodil appid connection add oauth:google --pool crm-suite \
--client-id … --client-secret …
# point the app at it — this is the whole integration
dodil ignite app deploy crm-core --auth pool:crm-suite
Connections
Turn on Google. That's the whole task.
Paste a client id and secret, flip the toggle. No redeploy, no library, no callback route in your app — the hosted login picks it up on the next sign-in.
Password reset and email verificationrequest, email, reset page
Cross-app SSOone login for every app in the pool
Sign-outend-session clears it everywhere
A separate plane, on purpose
Your app's users are not your Dodil users.
Your Dodil account is a platform principal — it can touch buckets, repos and deploys. The people who use the app you built live in their own pool, with their own issuer and their own signing keys. The two never share an issuer, and a platform grant can never arrive inside an app token. Your customers signing up does not widen your blast radius.
Two things worth knowing
An app scaled to zero cold-starts on the first login redirect — an image pull and a boot, so seconds. The hosted page holds its “Signing you in…” state throughout, but pin the app warm if that pause matters to you.
Dedicated SAML for corporate SSO is built but not yet enabled; it is reserved for the enterprise tier. Generic OIDC works today and covers most providers.
FAQ
Questions, answered.
Your users are one flag away.
Create a pool, add a connection, deploy with --auth pool:…