> ## Documentation Index
> Fetch the complete documentation index at: https://docs.connex.hybridsphere.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Zero-Trust Authentication & SSO

> Cryptographically signed JWT token claims and 120-second single-use ticket handshake protocol

CONNEX Cloud OS maintains a strict zero internal password storage policy, delegating core credential validation entirely to Firebase Authentication and Google Identity.

<Steps>
  <Step title="120-Second Single-Use Ticket Handshake">
    Cross-domain SSO handshakes utilize cryptographically secure UUIDv4 tickets mapped in Redis with a 120-second TTL. Tickets are burned immediately upon first exchange (`/api/v1/auth/exchange`), preventing replay attacks.
  </Step>

  <Step title="Mathematical Token-Level Authorization">
    User roles (`role`), jurisdictional tenancy (`home_country`), and admin privileges are signed directly into JWT ID token Custom Claims. Downstream microservices perform sub-1ms authorization checks without hitting central databases.
  </Step>

  <Step title="7 Standard Enterprise RBAC Roles">
    Access is rigorously governed across 7 explicit roles: `super_admin`, `founders`, `devops`, `bizops`, `demo_cx`, `customer_b2b`, and `customer_b2c`.
  </Step>
</Steps>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.